Impact
The vulnerability is an instance of improper privilege management (CWE-269) in the luci-app-samba4 package, where the file /usr/sbin/smbd is granted file.exec permission, allowing a delegated user to run the binary with arbitrary command‑line options. The process runs as root, meaning that a successful exploitation results in arbitrary command execution with system privileges.
Affected Systems
All OpenWrt devices that include the luci-app-samba4 package and have not applied the latest patch are affected. The specific affected firmware releases are not enumerated in the current advisory, so any unpatched installation of luci-app-samba4 should be considered vulnerable.
Risk and Exploitability
With a High CVSS base score of 8.7 the vulnerability presents a serious risk. The EPSS score is < 1%, indicating a low but nonzero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need authenticated access to the device and the ability to send SMB traffic that triggers global options. By controlling the message command option they can cause the privileged smbd process to execute arbitrary commands, effectively compromising the entire system.
OpenCVE Enrichment