Executive brief
luci-app-advanced-reboot is a web-based management interface for OpenWrt routers that allows administrators to reboot firmware partitions. In versions before 1.1.2-6, a flaw in its access control configuration allowed authenticated read-only users to execute arbitrary shell commands as the root user, potentially giving attackers full control of the router network and any data passing through it.
Technical details
The vulnerability exists in the rpcd ACL configuration file that grants file.exec permission on /bin/sh to read-level access. An authenticated delegated session with read-only access can supply caller-controlled parameters; rpcd authorizes the path and passes those arguments to the shell, enabling arbitrary command execution as root. The fix in 1.1.2-6 removes the broad file-exec grants, moves privileged actions into a dedicated write block, and handles device info gathering server-side.
Affected products
- OpenWrt luci-app-advanced-reboot prior to 1.1.2-6
Timeline
- 2026-06-15: patched: Version 1.1.2-6 released with security fix
- 2026-09-21: disclosed