CVE-2026-46368
luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.
Published:May 26, 2026
Last Modified:Jul 14, 2026
EPS:May 26, 2026
EPSS Score:0.06582
CVSS Score:8.8
Affected Products
Vendor
Product
Action
Vendor
Mossdef
Product
Luci-app-https-dns-proxy
Mossdef
Luci-app-https-dns-proxy
Vendor
Mossdef-org
Product
Luci-app-https-dns-proxy
Mossdef-org
Luci-app-https-dns-proxy
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
