CVE-2026-58000
HIGHluci-proto-openvpn - Command Injection via cl_meta Parameter in generateKey
Title source: cnaDescription
luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN protocol configuration access can inject arbitrary shell metacharacters into cl_meta to execute commands as root via the popen function.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-pm9w-522m-8rrh)
https://github.com/openwrt/luci/security/advisories/GHSA-pm9w-522m-8rrh
Patch patch
Patch Commit
https://github.com/openwrt/luci/commit/e4ff45ecbc6ad212951815c8c99b2749fbd7de6b
Third Party Advisory third-party-advisory
VulnCheck Advisory: luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKey
https://www.vulncheck.com/advisories/luci-proto-openvpn-command-injection-via-cl-meta-parameter-in-generatekey
Scores
CVSS v3
8.8
EPSS
0.0140
EPSS Percentile
69.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (4)
openwrt/luci
< 0.11.1
openwrt/luci
e4ff45ecbc6ad212951815c8c99b2749fbd7de6b
openwrt/luci-proto-openvpn
< 0.11.1
openwrt/luci-proto-openvpn
e4ff45ecbc6ad212951815c8c99b2749fbd7de6b
Published
Jun 29, 2026
Tracked Since
Jun 30, 2026