OpenWRT LuCI是OpenWRT社区开源的一个网页管理界面。 OpenWRT LuCI存在输入验证错误漏洞,该漏洞源于文件上传期间对instance_name2参数验证不当,导致路径遍历,可能允许经过身份验证的攻击者在预期目录之外写入任意文件,并通过在系统目录中放置SSH密钥获取持久的root代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-72842 | 9.9 CRITICAL | OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass |
| CVE-2026-72840 | 8.8 HIGH | OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write |
No comments yet