VYPR

luci-mod-system-mounts

by Openwrt

CVEs (1)

  • CVE-2026-72840HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries…