Description
luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.
Published: 2026-09-21
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Root Command Execution via Delegated User
Action: Immediate Patch
AI Analysis

Impact

The RPC method luci.adblock‑fast.setCronEntry accepts an entry argument that may contain carriage‑return or line‑feed characters. During serialization the method writes the entry directly to /etc/crontabs/root as if it were a single logical line. If newline characters are present, the resulting file contains multiple physical cron entries that are executed with root privileges whenever cron processes the file. This leads to persistent command execution as UID 0. The flaw is an instance of improper neutralization of CRLF characters in a system command context (CWE‑93).

Affected Systems

The vulnerability is present in the luci‑app‑adblock‑fast package shipped with OpenWrt. Versions older than 1.2.4‑2 are affected. Only users with the write ACL for the RPC method luci‑app‑adblock‑fast.setCronEntry can trigger the flaw. No other OpenWrt packages are impacted directly.

Risk and Exploitability

The CVSS base score of 8.8 indicates high severity. Exploitation requires a legitimate authenticated session with write privileges to the RPC method; it is not remotely exploitable without prior authentication. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. However, once the conditions are met, the attacker achieves persistent root‑level command execution, which represents an elevated privilege escalation threat. No public exploits have been reported.

Generated by OpenCVE AI on September 21, 2026 at 20:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade luci‑app‑adblock‑fast to 1.2.4‑2 or newer
  • Remove any malicious entries from /etc/crontabs/root and restart cron
  • Restrict the write ACL for luci‑app‑adblock‑fast.setCronEntry to trusted users

Generated by OpenCVE AI on September 21, 2026 at 20:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.
Title luci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entries
Weaknesses CWE-93
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-29T14:01:11.023Z

Reserved: 2026-06-16T15:13:28.165Z

Link: CVE-2026-55159

cve-icon Vulnrichment

Updated: 2026-09-29T14:00:45.462Z

cve-icon NVD

Status : Deferred

Published: 2026-09-21T20:17:26.500

Modified: 2026-09-29T14:17:20.817

Link: CVE-2026-55159

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T21:00:07Z

Weaknesses
  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')