Junglewise Threat Intelligence

CVE-2026-55897: OpenWrt luci-app-advanced-reboot privilege escalation via rpcd ACL

CVE-2026-55897 · Severity: high · CVSS 8.8 · Published 2026-09-21

Vendors: OpenWrt.

Executive brief

luci-app-advanced-reboot is a web-based management interface for OpenWrt routers that allows administrators to reboot firmware partitions. In versions before 1.1.2-6, a flaw in its access control configuration allowed authenticated read-only users to execute arbitrary shell commands as the root user, potentially giving attackers full control of the router network and any data passing through it.

Technical details

The vulnerability exists in the rpcd ACL configuration file that grants file.exec permission on /bin/sh to read-level access. An authenticated delegated session with read-only access can supply caller-controlled parameters; rpcd authorizes the path and passes those arguments to the shell, enabling arbitrary command execution as root. The fix in 1.1.2-6 removes the broad file-exec grants, moves privileged actions into a dedicated write block, and handles device info gathering server-side.

Affected products

  • OpenWrt luci-app-advanced-reboot prior to 1.1.2-6

Timeline

  • 2026-06-15: patched: Version 1.1.2-6 released with security fix
  • 2026-09-21: disclosed

References