Privilege Escalation Vulnerability in OpenWRT Luci by VitoCrl
CVE-2024-51240

Currently unrated

Key Information:

Vendor

OpenWRT

Vendor
CVE Published:
5 November 2024

What is CVE-2024-51240?

The luci-mod-rpc package in OpenWRT Luci LTS has a critical vulnerability where an attacker can exploit the exposed JSON-RPC API to escalate privileges from an admin account to root. This presents a serious security risk, allowing unauthorized access and control over the system. Users are urged to assess their installations and implement necessary mitigations.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.