VYPR

luci-app-travelmate

by Openwrt

CVEs (1)

  • CVE-2026-58652HigJul 2, 2026
    risk 0.00cvss 7.5epss 0.00

    luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker…