OpenWrt disclosed a high-severity command injection vulnerability in luci-proto-openvpn through version 0.11.1 that allows an authenticated LuCI user to execute arbitrary commands as root. The flaw affects the generateKey ubus method in the LuCI OpenVPN rpcd backend, where the caller-controlled cl_meta parameter is inserted into a shell command without proper quoting or escaping. Because rpcd runs with root privileges, an attacker with access to the OpenVPN protocol configuration can remotely achieve full device compromise, including reading or modifying files, changing firewall and network settings, and installing persistence.
Advisory details said the official LuCI front end was only accidentally safe because it base64-encoded cl_meta, while the backend still accepted raw values through direct ubus or LuCI RPC calls without server-side validation. A proof of concept reportedly executed id as root and created /tmp/INJECTED_PROOF on an OpenWrt 23.05.5 root filesystem. OpenWrt fixed the issue in commit e4ff45e, which wraps cl_meta with shellquote(), and users were urged to update luci-proto-openvpn, apply the patch, restrict configuration access, and monitor for suspicious command execution.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-58000 was published for a high-severity command injection vulnerability affecting luci-proto-openvpn through version 0.11.1. The issue allows an authenticated LuCI user with OpenVPN protocol configuration access to execute arbitrary commands as root, and references commit e4ff45e as the fix.
A GitHub security advisory disclosed that the luci.openvpn generateKey ubus method allowed authenticated users with OpenVPN configuration access to inject commands as root through the unescaped cl_meta parameter. The advisory also noted a proof of concept that executed id as root and created /tmp/INJECTED_PROOF on an OpenWrt 23.05.5 rootfs.
OpenWrt committed a fix for a shell code injection issue in luci-proto-openvpn by wrapping the generateKey method's cl_meta argument with shellquote(). The commit was made by Jo-Philipp Wich and addresses command execution risk in the OpenVPN RPC backend.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcevulncheck.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.