CVE Feed

    Dashboard / CVE / CVE-2026-46368

    CVE-2026-46368

    luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' parameter of a ubus RPC call to luci.https-dns-proxy setInitAction, resulting in arbitrary command execution as root on the underlying device. Core OpenWrt is not affected; only installations that have opted in to the luci-app-https-dns-proxy package are vulnerable.

    Published:May 26, 2026
    Last Modified:Jul 14, 2026
    EPS:May 26, 2026
    EPSS Score:0.06582
    CVSS Score:8.8

    Affected Products

    Vendor
    Mossdef
    Product
    Luci-app-https-dns-proxy
    Vendor
    Mossdef-org
    Product
    Luci-app-https-dns-proxy

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High