Fwd: Critical Security Vulnerability Reported
OJ
ojayheggs at gmail.com
Thu Aug 27 14:10:47 PDT 2026
Hi all,
I have been trying to disclose 2 security issues but don't seem to be
getting replies - can this please be reviewed as I have concerns that
these are high/critical in risk.
Kind regards,
Oskar
---------- Forwarded message ---------
From: OJ <ojayheggs at gmail.com>
Date: Thu, 20 Aug 2026 at 18:16
Subject: Re: Critical Security Vulnerability Reported
To: Hauke Mehrtens <hauke at hauke-m.de>
Hi Hauke,
Just wanted to check in- as the severity for these issues has the
potential to be critical in nature.
Thanks
On Fri, 14 Aug 2026 at 16:55, OJ <ojayheggs at gmail.com> wrote:
>
> Hi Hauke,
>
> Have you got my reported findings OK?
>
> Kind regards,
> Oskar
>
> On Tue, 11 Aug 2026 at 21:24, OJ <ojayheggs at gmail.com> wrote:
>>
>> Hi Hauke,
>>
>> I would prefer not to submit these to the public mailing list, as in OpenWRT's wiki under the security section (https://openwrt.org/docs/guide-developer/security) it states the following:
>>
>> "Please avoid providing detailed information on the public mailing list that would aid exploitation, such as the vulnerable component and exploit details"
>>
>> I have included the original emails as an attachment here in PDF format.
>>
>> Kind regards,
>> Oskar
>>
>> On Tue, 11 Aug 2026 at 21:18, Hauke Mehrtens <hauke at hauke-m.de> wrote:
>>>
>>> Hi,
>>>
>>> I can not find them, just post them directly to the public mailing list:
>>> openwrt-adm at lists.openwrt.org
>>>
>>> Hauke
>>>
>>> On 8/11/26 20:25, OJ wrote:
>>> > Hi Hauke,
>>> >
>>> > Did you manage to find my emails OK?
>>> >
>>> > Kind regards,
>>> > Oskar
>>> >
>>> > On Sun, 9 Aug 2026 at 22:14, OJ <ojayheggs at gmail.com
>>> > <mailto:ojayheggs at gmail.com>> wrote:
>>> >
>>> > Hi Hauke,
>>> >
>>> > I have actually reported an additional vulnerability since this email
>>> >
>>> > Subject: Security Vulnerability - OS command injection via unquoted
>>> > shell pipe in luci-app-commands "Custom Commands" argument handling
>>> > Sent on Friday the 31st of July
>>> >
>>> > Subject: Security Vulnerability - Remote Code Execution in DDNS
>>> > (luci-app-ddns)
>>> > Sent on Saturday the 8th of July, yesterday.
>>> >
>>> > Thank you for the reply,
>>> > Oskar
>>> >
>>> > On Sun, 9 Aug 2026 at 17:12, Hauke Mehrtens <hauke at hauke-m.de
>>> > <mailto:hauke at hauke-m.de>> wrote:
>>> >
>>> > On 7/31/26 20:50, OJ wrote:
>>> > > Hello,
>>> > >
>>> > > I'm just writing to inform you that I have reported a critical
>>> > > security vulnerability to the contact at openwrt.org
>>> > <mailto:contact at openwrt.org> email. Due to the
>>> > > critical nature I thought it was best to reach out to this public
>>> > > mailing list.
>>> > >
>>> > > Kind regards,
>>> > > Oskar
>>> > >
>>> > > _______________________________________________
>>> > > openwrt-adm mailing list
>>> > > openwrt-adm at lists.openwrt.org <mailto:openwrt-
>>> > adm at lists.openwrt.org>
>>> > > https://lists.openwrt.org/mailman/listinfo/openwrt-adm
>>> > <https://lists.openwrt.org/mailman/listinfo/openwrt-adm>
>>> >
>>> > Hi Oskar,
>>> >
>>> > I can not find a mail from your mail address in the
>>> > contact at openwrt.org <mailto:contact at openwrt.org>
>>> > mailbox. When did you send it and what was the subject?
>>> >
>>> > Hauke
>>> >
>>>
More information about the openwrt-adm
mailing list