Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-46368— luci-app-https-dns-proxy Authenticated Command Injection via setInitAction

CVSS 8.8 · High EPSS 0.06% · P19

Affected Version Matrix 1

VendorProductVersion RangeStatus
mossdef-orgluci-app-https-dns-proxy≤ 2025.12.29-5affected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46368

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
Source: NVD (National Vulnerability Database)
Vulnerability Description
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Source: NVD (National Vulnerability Database)
Vulnerability Title
luci-app-https-dns-proxy 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
luci-app-https-dns-proxy是Stan Grishin个人开发者的一款OpenWrt的DNS-over-HTTPS代理Web管理界面。 luci-app-https-dns-proxy 2025.12.29-5及之前版本存在命令注入漏洞,该漏洞源于setInitAction函数中存在命令注入,可能导致认证用户通过name参数注入shell元字符执行任意命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
mossdef-orgluci-app-https-dns-proxy 0 ~ 2025.12.29-5 -

II. Public POCs for CVE-2026-46368

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 5863 chars
Paid plan includes:
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-46368

登录查看更多情报信息。

Vendor Advisories for CVE-2026-46368 (1)

Exploits & Public PoCs for CVE-2026-46368 (1)

Vendor Pages for CVE-2026-46368 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-46368

No comments yet


Leave a comment