[SECURITY] Potential High-Severity Command Injection in LuCI (Password Handling)

Sri Sowmya Nemani nemanisrisowmya at gmail.com
Wed Nov 19 10:53:36 PST 2025


Hello OpenWrt Administrative Team,

I am writing to follow up on a confidential report I sent to
contact at openwrt.org on Nov 17, 2025, titled:

[SECURITY] Potential High-Severity Command Injection in LuCI (Password Handling)

I have not received an acknowledgement after 2 days. Could you please
confirm with the security team that the report was successfully
received and is being processed?

Thank you,

Sri Sowmya Nemani



More information about the openwrt-adm mailing list