VYPR

luci-proto-openvpn

by Openwrt

CVEs (1)

  • CVE-2026-58000Jun 29, 2026
    risk 0.00cvss epss 0.01

    luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN…