top of page
perceptive_background_267k.jpg

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS…

Published:

2 augustus 2026 om 22:00:00

Alert date:

3 augustus 2026 om 15:06:10

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Network Infrastructure, Zero-Day Vulnerabilities

A critical OS command injection vulnerability exists in OpenWrt's luci-app-dockerman package, specifically in LuCI master and openwrt-25.12 snapshots that include the ucode docker_rpc.uc RPC backend. The vulnerability stems from the run_ttyd handler building shell commands from user-controlled fields (id, cmd, uid) without proper sanitization or quoting, passing them directly to system() in the rpcd root context. The package's read ACL inadvertently exposes the docker.container.ttyd_start mutating method via broad ubus access grants. An authenticated attacker with only the luci-app-dockerman read ACL can inject shell metacharacters to achieve arbitrary command execution as root via HTTP POST to /ubus. Older versions openwrt-24.10 and openwrt-23.05 are not affected as they lack this backend. No patched version was available at the time of the advisory, though GitHub commits have been referenced as potential fixes.

Technical details

Mitigation steps:

Affected products:

OpenWrt luci-app-dockerman
LuCI master
openwrt-25.12

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page