Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
luci-app-https-dns-proxy Authenticated Command Injection via setInitAction
Vulnerability Description
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
luci-app-https-dns-proxy 命令注入漏洞
Vulnerability Description
luci-app-https-dns-proxy是Stan Grishin个人开发者的一款OpenWrt的DNS-over-HTTPS代理Web管理界面。 luci-app-https-dns-proxy 2025.12.29-5及之前版本存在命令注入漏洞,该漏洞源于setInitAction函数中存在命令注入,可能导致认证用户通过name参数注入shell元字符执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A