{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/luci-app-dockerman/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-69096"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["luci-app-dockerman"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenWrt"],"content_html":"\u003cp\u003eCVE-2026-69096 describes a critical OS command injection vulnerability within the luci-app-dockerman package for OpenWrt, specifically affecting LuCI master and openwrt-25.12 snapshot releases. The vulnerability originates in the ucode-based docker_rpc.uc RPC backend, which was introduced during a recent transition from JS to ucode. Due to an overly permissive read ACL, the docker.container.ttyd_start method is exposed to users who should only possess read-only privileges.\u003c/p\u003e\n\u003cp\u003eThe vulnerable code within the run_ttyd handler fails to properly sanitize or quote input parameters - specifically 'id', 'cmd', and 'uid' - before passing them to the system() function. Because the rpcd process operates with root-level privileges, an authenticated attacker can leverage this misconfiguration to perform arbitrary command execution. This flaw is restricted to versions containing the new ucode backend, meaning older stable releases like openwrt-24.10 and openwrt-23.05 remain unaffected. As of the initial advisory, no patch has been released to mitigate this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an authenticated attacker full root-level control over the OpenWrt device. This allows for total system compromise, including the interception of network traffic, persistence installation, and potential lateral movement into the local network. Given the nature of OpenWrt deployments as edge routers and gateways, this vulnerability significantly increases the risk of man-in-the-middle attacks and internal network exposure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAudit existing OpenWrt deployments to identify the use of the luci-app-dockerman package on openwrt-25.12 or LuCI master snapshots.\u003c/li\u003e\n\u003cli\u003eMonitor ubus request logs for suspicious JSON-RPC calls targeting the docker.container.ttyd_start method, specifically observing unexpected shell metacharacters in parameter fields.\u003c/li\u003e\n\u003cli\u003eIf the package is not required, uninstall luci-app-dockerman until a vendor-supplied patch is available.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall controls to limit access to the web interface (LuCI) and the ubus RPC endpoint to trusted internal management subnets only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T16:06:45Z","date_published":"2026-08-03T16:06:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-openwrt-luci-cmd-injection/","summary":"An authenticated OS command injection vulnerability in the docker_rpc.uc backend of luci-app-dockerman allows attackers with read-only ACLs to execute arbitrary commands as root via the /ubus RPC endpoint.","title":"CVE-2026-69096: OS Command Injection in OpenWrt luci-app-dockerman","url":"https://feed.craftedsignal.io/briefs/2026-08-openwrt-luci-cmd-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Luci-App-Dockerman","version":"https://jsonfeed.org/version/1.1"}