CVE-2026-55159: Openwrt Luci-App-Adblock-Fast
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and serializes it into /etc/crontabs/root as though it were one logical line. An authenticated delegated user with the luci-app-adblock-fast write ACL can therefore create an additional physical root cron entry through applications/luci-app-adblock-fast/root/usr/share/rpcd/ucode/luci.adblock-fast, resulting in persistent command execution as UID 0 when cron runs. The issue is not demonstrated for unauthenticated callers or users without the component write ACL. This vulnerability is fixed in 1.2.4-2.
Affected products
- Openwrt Luci-App-Adblock-Fast: before 1.2.4-2 (fixed in 1.2.4-2)
Published 2026-09-21. Last modified 2026-09-29.