Executive brief
luci-app-adblock-fast is a web-based configuration tool for OpenWrt's DNS-based ad-blocking service. An authenticated user with write access can inject newline characters into cron job entries to create arbitrary additional root cron jobs, leading to command execution as the root user (UID 0) when the cron scheduler runs.
Technical details
The luci.adblock-fast.setCronEntry RPC method fails to sanitize carriage-return and line-feed characters in its entry parameter before writing to /etc/crontabs/root, allowing an authenticated attacker with the luci-app-adblock-fast write ACL to inject additional cron lines. The vulnerability requires authentication and the component-specific ACL permission, but not user interaction. The fix in 1.2.4-2 removes the vulnerable setCronEntry RPC and replaces it with syncCron, which validates schedule fields as bounded integers server-side.
Affected products
- OpenWrt luci-app-adblock-fast prior to 1.2.4-2
Timeline
- 2026-09-21: disclosed
- 2026-06-15: patched