VYPR

luci-proto-openvpn

by Openwrt

CVEs (2)

  • CVE-2026-72841CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.01

    luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code…

  • CVE-2026-58000HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.03

    luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN…