Impact
The RPC method luci.adblock‑fast.setCronEntry accepts an entry argument that may contain carriage‑return or line‑feed characters. During serialization the method writes the entry directly to /etc/crontabs/root as if it were a single logical line. If newline characters are present, the resulting file contains multiple physical cron entries that are executed with root privileges whenever cron processes the file. This leads to persistent command execution as UID 0. The flaw is an instance of improper neutralization of CRLF characters in a system command context (CWE‑93).
Affected Systems
The vulnerability is present in the luci‑app‑adblock‑fast package shipped with OpenWrt. Versions older than 1.2.4‑2 are affected. Only users with the write ACL for the RPC method luci‑app‑adblock‑fast.setCronEntry can trigger the flaw. No other OpenWrt packages are impacted directly.
Risk and Exploitability
The CVSS base score of 8.8 indicates high severity. Exploitation requires a legitimate authenticated session with write privileges to the RPC method; it is not remotely exploitable without prior authentication. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, once the conditions are met, the attacker achieves persistent root‑level command execution, which represents an elevated privilege escalation threat. No public exploits have been reported.
OpenCVE Enrichment