Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-55159

Опубликовано: 21 сент. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.

EPSS

Процентиль: 41%
0.0049
Низкий

8.8 High

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 8.8
debian
2 дня назад

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-block ...

EPSS

Процентиль: 41%
0.0049
Низкий

8.8 High

CVSS3

Дефекты

CWE-93