Fwd: Critical Security Vulnerability Reported

OJ ojayheggs at gmail.com
Thu Aug 27 14:10:47 PDT 2026


Hi all,

I have been trying to disclose 2 security issues but don't seem to be
getting replies - can this please be reviewed as I have concerns that
these are high/critical in risk.

Kind regards,
Oskar

---------- Forwarded message ---------
From: OJ <ojayheggs at gmail.com>
Date: Thu, 20 Aug 2026 at 18:16
Subject: Re: Critical Security Vulnerability Reported
To: Hauke Mehrtens <hauke at hauke-m.de>


Hi Hauke,

Just wanted to check in- as the severity for these issues has the
potential to be critical in nature.

Thanks

On Fri, 14 Aug 2026 at 16:55, OJ <ojayheggs at gmail.com> wrote:
>
> Hi Hauke,
>
> Have you got my reported findings OK?
>
> Kind regards,
> Oskar
>
> On Tue, 11 Aug 2026 at 21:24, OJ <ojayheggs at gmail.com> wrote:
>>
>> Hi Hauke,
>>
>> I would prefer not to submit these to the public mailing list, as in OpenWRT's wiki under the security section (https://openwrt.org/docs/guide-developer/security) it states the following:
>>
>> "Please avoid providing detailed information on the public mailing list that would aid exploitation, such as the vulnerable component and exploit details"
>>
>> I have included the original emails as an attachment here in PDF format.
>>
>> Kind regards,
>> Oskar
>>
>> On Tue, 11 Aug 2026 at 21:18, Hauke Mehrtens <hauke at hauke-m.de> wrote:
>>>
>>> Hi,
>>>
>>> I can not find them, just post them directly to the public mailing list:
>>> openwrt-adm at lists.openwrt.org
>>>
>>> Hauke
>>>
>>> On 8/11/26 20:25, OJ wrote:
>>> > Hi Hauke,
>>> >
>>> > Did you manage to find my emails OK?
>>> >
>>> > Kind regards,
>>> > Oskar
>>> >
>>> > On Sun, 9 Aug 2026 at 22:14, OJ <ojayheggs at gmail.com
>>> > <mailto:ojayheggs at gmail.com>> wrote:
>>> >
>>> >     Hi Hauke,
>>> >
>>> >     I have actually reported an additional vulnerability since this email
>>> >
>>> >     Subject: Security Vulnerability - OS command injection via unquoted
>>> >     shell pipe in luci-app-commands "Custom Commands" argument handling
>>> >     Sent on Friday the 31st of July
>>> >
>>> >     Subject: Security Vulnerability - Remote Code Execution in DDNS
>>> >     (luci-app-ddns)
>>> >     Sent on Saturday the 8th of July, yesterday.
>>> >
>>> >     Thank you for the reply,
>>> >     Oskar
>>> >
>>> >     On Sun, 9 Aug 2026 at 17:12, Hauke Mehrtens <hauke at hauke-m.de
>>> >     <mailto:hauke at hauke-m.de>> wrote:
>>> >
>>> >         On 7/31/26 20:50, OJ wrote:
>>> >          > Hello,
>>> >          >
>>> >          > I'm just writing to inform you that I have reported a critical
>>> >          > security vulnerability to the contact at openwrt.org
>>> >         <mailto:contact at openwrt.org> email. Due to the
>>> >          > critical nature I thought it was best to reach out to this public
>>> >          > mailing list.
>>> >          >
>>> >          > Kind regards,
>>> >          > Oskar
>>> >          >
>>> >          > _______________________________________________
>>> >          > openwrt-adm mailing list
>>> >          > openwrt-adm at lists.openwrt.org <mailto:openwrt-
>>> >         adm at lists.openwrt.org>
>>> >          > https://lists.openwrt.org/mailman/listinfo/openwrt-adm
>>> >         <https://lists.openwrt.org/mailman/listinfo/openwrt-adm>
>>> >
>>> >         Hi Oskar,
>>> >
>>> >         I can not find a mail from your mail address in the
>>> >         contact at openwrt.org <mailto:contact at openwrt.org>
>>> >         mailbox. When did you send it and what was the subject?
>>> >
>>> >         Hauke
>>> >
>>>



More information about the openwrt-adm mailing list