Junglewise Threat Intelligence

CVE-2026-72841: OpenWrt luci-app-openvpn path traversal and arbitrary file write

CVE-2026-72841 · Severity: critical · CVSS 9.9 · Published 2026-08-13

Vendors: OpenWrt.

Executive brief

luci-app-openvpn is a web interface component for managing OpenVPN configurations on OpenWrt routers. Authenticated users with read-only access can exploit a path traversal flaw to upload arbitrary files outside the intended directory, enabling persistent root access by injecting SSH keys into system directories that execute on device reboot. This gives attackers complete control over the router.

Technical details

The vulnerability is a path traversal flaw (CWE-73: External Control of File Name or Path) in the luci-app-openvpn file upload handler. The application fails to sanitize the instance_name2 parameter, directly concatenating it to /etc/openvpn/ without enforcing directory boundaries or validating input. An authenticated attacker with read-only access to the OpenVPN configuration interface can manipulate instance_name2 to escape the intended directory and write files to arbitrary locations. By uploading shell commands to system directories (e.g., /etc/dropbear/authorized_keys), the attacker achieves remote code execution with root privileges on system reboot, enabling persistent SSH access and full device compromise. Patches are not yet available.

Affected products

  • OpenWrt luci-app-openvpn 25.12.2

Timeline

  • 2026-07-21: disclosed: GitHub Security Advisory GHSA-jjcx-c284-2qv8 published
  • 2026-08-13: advisory: CVE-2026-72841 published on NVD

References