← Back to search

CVE-2026-55159

8.8 HIGHpublic exploit available

Published 2026-09-21 · Updated 2026-09-24

AI risk analysis

Summary
The flaw allows an authenticated delegated user to inject malicious cron entries, leading to persistent command execution as root.
Exploitability
Exploitation requires authentication and access to the luci-app-adblock-fast write ACL. The vulnerability is not demonstrated for unauthenticated callers.
Blast radius
If exploited, the impact is severe, as it allows for persistent root-level command execution.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to version 1.2.4-2 or later.
rceauth-bypasswebcronopenwrt

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-93

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.