Impact
luci-app-lxc for OpenWrt contains an ACL inconsistency that lets low‑privileged authenticated LuCI users reach backend container‑management endpoints that should be protected. By submitting a crafted lxc_name value containing the encoded path traversal sequence "/.%2E", an attacker can escape the intended container directory and trigger host‑side scripts exposed by the lxc.hook.start-host hook, enabling the execution of code as root on the OpenWrt device.
Affected Systems
The vulnerability affects any installation of the luci-app-lxc package on OpenWrt routers. Version information is not specified in the advisory, so all released versions of the application should be considered vulnerable until a fixed package is deployed.
Risk and Exploitability
The CVSS score of 9.4 classifies this flaw as critical. Exploitation requires an authenticated LuCI session, which is typically available to users with at least local login rights, and the attacker must supply a specific parameter value; however, once authenticated, the attacker can craft the request over the network. The EPSS score is currently unavailable and the vulnerability is not listed in the CISA KEV catalog, although the high severity suggests that active exploitation is a real threat. The attack surface is therefore router with enabled luci-app-lxc and accessible network access to LuCI can be targeted.
OpenCVE Enrichment