luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject arbitrary shell metacharacters into cl_meta to execute commands as root via the popen function.
References
Configurations
No configuration.
History
29 Jun 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openwrt/luci/security/advisories/GHSA-pm9w-522m-8rrh - |
29 Jun 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-29 19:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-58000
Mitre link : CVE-2026-58000
CVE.ORG link : CVE-2026-58000
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
