漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
Vulnerability Description
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
luci-app-https-dns-proxy 命令注入漏洞
Vulnerability Description
luci-app-https-dns-proxy是Stan Grishin个人开发者的一款OpenWrt的DNS-over-HTTPS代理Web管理界面。 luci-app-https-dns-proxy 2025.12.29-5及之前版本存在命令注入漏洞,该漏洞源于setInitAction函数中存在命令注入,可能导致认证用户通过name参数注入shell元字符执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A