top of page
perceptive_background_267k.jpg

luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted c…

Published:

1 juli 2026 om 22:00:00

Alert date:

2 juli 2026 om 14:04:36

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities, Identity & Access

CVE-2026-58652 describes a privilege escalation vulnerability in luci-app-travelmate and the travelmate package for OpenWrt. A session with luci-app-travelmate write ACL gains config-wide UCI write access to travelmate configuration. The LuCI frontend restricts the auto-login script picker to /etc/travelmate/*.login, but this restriction is only enforced client-side. The backend travelmate service runs as root and directly executes UCI 'script' and 'script_args' values without validation when the captive-portal auto-login branch is triggered. An attacker with delegated write permissions can set the script parameter to /bin/sh and supply arbitrary arguments, achieving root-level command execution. The vulnerability is confirmed in versions 2.4.5-r3 and 2.4.6-1, with no patched version available at time of disclosure.

Technical details

Mitigation steps:

Affected products:

luci-app-travelmate 2.4.5-r3
travelmate 2.4.5-r3
travelmate 2.4.6-1
OpenWrt LuCI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page