Impact
The vulnerability in luci-app-travelmate is a command injection flaw (CWE‑78). An attacker who can write to the LuCI or rpcd configuration can set the 'script' and 'script_args' options. The travelmate service, which runs as root, reads these values and executes them when the captive‑portal auto the attacker can run arbitrary commands as root, achieving full system compromise.
Affected Systems
OpenWrt luci-app-travelmate and the travelmate package are affected. Versions 2.4.5‑r3 and the subsequent 2.4.6‑1 release contain the flaw, and no patched version is currently available. All systems deploying these packages remain vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 7.7, indicating high severity. Its EPSS score is less than 1%, suggesting a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is via an entity that has delegated write permissions through LuCI or rpcd. Because the flaw allows privilege escalation when write access is available, the risk is high for systems that expose the LuCI interface to untrusted parties.
OpenCVE Enrichment