Junglewise Threat Intelligence

CVE-2026-55159: luci-app-adblock-fast command injection in RPC cron entry

CVE-2026-55159 · Severity: high · CVSS 8.8 · Published 2026-09-21

Vendors: OpenWrt.

Executive brief

luci-app-adblock-fast is a web-based configuration tool for OpenWrt's DNS-based ad-blocking service. An authenticated user with write access can inject newline characters into cron job entries to create arbitrary additional root cron jobs, leading to command execution as the root user (UID 0) when the cron scheduler runs.

Technical details

The luci.adblock-fast.setCronEntry RPC method fails to sanitize carriage-return and line-feed characters in its entry parameter before writing to /etc/crontabs/root, allowing an authenticated attacker with the luci-app-adblock-fast write ACL to inject additional cron lines. The vulnerability requires authentication and the component-specific ACL permission, but not user interaction. The fix in 1.2.4-2 removes the vulnerable setCronEntry RPC and replaces it with syncCron, which validates schedule fields as bounded integers server-side.

Affected products

  • OpenWrt luci-app-adblock-fast prior to 1.2.4-2

Timeline

  • 2026-09-21: disclosed
  • 2026-06-15: patched

References