Description
An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.
Published: 2026-10-09
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A flaw in iStoreOS version 24.10.7 and earlier allows a remote attacker to execute arbitrary code by providing a malicious value in the task_id parameter within the tasks-lib.lua script. The vulnerability can lead to full system compromise, granting the attacker control over the affected device. The weakness stems from insufficient validation of the task_id argument, enabling unintended code execution. If exploited, confidentiality, integrity, and availability of the device and any connected services could be severely affected.

Affected Systems

The affected product is iStoreOS, specifically releases 24.10.7 and earlier. The vulnerability resides in the tasks-lib.lua component used to handle task identifiers. No other vendors or versions are mentioned.

Risk and Exploitability

The flaw permits arbitrary code execution, representing a high severity risk. Because the EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, concrete exploitation statistics are missing; however, the nature of the flaw strongly suggests it could be actively exploited. The attack vector is remote, likely via an unauthenticated HTTP request to the router’s task management endpoint. An attacker only needs to supply a crafted task_id value to trigger arbitrary code execution.

Generated by OpenCVE AI on October 9, 2026 at 20:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade iStoreOS to a version newer than 24.10.7 when available.
  • Restrict external access to the task management interface, for example by configuring firewall rules or network segmentation.
  • Monitor inbound traffic for anomalous task_id requests and block sources exhibiting suspicious patterns.

Generated by OpenCVE AI on October 9, 2026 at 20:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via task_id in iStoreOS
Weaknesses CWE-20
CWE-94

Fri, 09 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Description An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T19:04:04.637Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-78797

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T20:17:11.117

Modified: 2026-10-09T20:17:11.117

Link: CVE-2026-78797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T21:00:13Z

Weaknesses
  • CWE-20

    Improper Input Validation

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')