Description
luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject arbitrary shell metacharacters into cl_meta to execute commands as root via the popen function.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
Low
User Interaction
None
Confidentiality (Vulnerable System)
High
Integrity (Vulnerable System)
High
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- openwrt / luci0 – 0.11.1
- openwrt / lucie4ff45ecbc6ad212951815c8c99b2749fbd7de6b – e4ff45ecbc6ad212951815c8c99b2749fbd7de6b
- openwrt / luci-proto-openvpn0 – 0.11.1
- openwrt / luci-proto-openvpne4ff45ecbc6ad212951815c8c99b2749fbd7de6b – e4ff45ecbc6ad212951815c8c99b2749fbd7de6b
References
Updated 24m ago · 8 sources