Executive brief
luci-app-https-dns-proxy is a web interface add-on for OpenWrt's HTTPS DNS proxy service. An authenticated user can inject shell metacharacters through the configuration interface to execute arbitrary commands with root privileges, enabling full compromise of the device without requiring elevated permissions.
Technical details
The vulnerability is a command injection (CWE-77) in the setInitAction ubus RPC handler that fails to sanitize the name parameter before passing it to the shell via eval(). An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters (such as semicolons, backticks, or pipes) in the name parameter to execute arbitrary commands as root. The vulnerable component is located in /usr/libexec/rpcd/luci.https-dns-proxy. The attack requires network reachability to the LuCI web interface and valid authentication credentials; exploitation results in arbitrary command execution and full system compromise. The fix (PR #15, merged 2026-01-16) adds validation to ensure the name parameter matches the expected package name before processing.
Affected products
- OpenWrt luci-app-https-dns-proxy through 2025.12.29-5
Timeline
- 2026-01-16: disclosed
- 2026-01-16: patched: Fix merged in PR #15
- 2026-08-27: advisory