PT-2024-7903 · Openwrt · Openwrt Luci Lts

Fabrizio Passerini

+1

·

Published

2024-11-05

·

Updated

2025-09-12

·

CVE-2024-51240

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenWRT Luci LTS (affected versions not specified)
Description The issue is related to the luci-mod-rpc package in OpenWRT Luci LTS, which allows for privilege escalation from an admin account to root via the JSON-RPC-API. This is due to insufficient protection of registration data in the LuCI web interface. An attacker can exploit this issue to gain root privileges remotely.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09407
CVE-2024-51240

Affected Products

Openwrt Luci Lts