Critical Security Vulnerability Reported
Etienne Champetier
champetier.etienne at gmail.com
Thu Aug 27 16:55:57 PDT 2026
Hi Oskar,
Le jeu. 27 août 2026 à 17:12, OJ <ojayheggs at gmail.com> a écrit :
>
> Hi all,
>
> I have been trying to disclose 2 security issues but don't seem to be
> getting replies - can this please be reviewed as I have concerns that
> these are high/critical in risk.
Can you report the issues via github ?
https://github.com/openwrt/openwrt/security/advisories/new
https://github.com/openwrt/luci/security/advisories/new
https://github.com/openwrt/packages/security/advisories/new
(please pick the correct repo)
Best
Etienne
>
> Kind regards,
> Oskar
>
> ---------- Forwarded message ---------
> From: OJ <ojayheggs at gmail.com>
> Date: Thu, 20 Aug 2026 at 18:16
> Subject: Re: Critical Security Vulnerability Reported
> To: Hauke Mehrtens <hauke at hauke-m.de>
>
>
> Hi Hauke,
>
> Just wanted to check in- as the severity for these issues has the
> potential to be critical in nature.
>
> Thanks
>
> On Fri, 14 Aug 2026 at 16:55, OJ <ojayheggs at gmail.com> wrote:
> >
> > Hi Hauke,
> >
> > Have you got my reported findings OK?
> >
> > Kind regards,
> > Oskar
> >
> > On Tue, 11 Aug 2026 at 21:24, OJ <ojayheggs at gmail.com> wrote:
> >>
> >> Hi Hauke,
> >>
> >> I would prefer not to submit these to the public mailing list, as in OpenWRT's wiki under the security section (https://openwrt.org/docs/guide-developer/security) it states the following:
> >>
> >> "Please avoid providing detailed information on the public mailing list that would aid exploitation, such as the vulnerable component and exploit details"
> >>
> >> I have included the original emails as an attachment here in PDF format.
> >>
> >> Kind regards,
> >> Oskar
> >>
> >> On Tue, 11 Aug 2026 at 21:18, Hauke Mehrtens <hauke at hauke-m.de> wrote:
> >>>
> >>> Hi,
> >>>
> >>> I can not find them, just post them directly to the public mailing list:
> >>> openwrt-adm at lists.openwrt.org
> >>>
> >>> Hauke
> >>>
> >>> On 8/11/26 20:25, OJ wrote:
> >>> > Hi Hauke,
> >>> >
> >>> > Did you manage to find my emails OK?
> >>> >
> >>> > Kind regards,
> >>> > Oskar
> >>> >
> >>> > On Sun, 9 Aug 2026 at 22:14, OJ <ojayheggs at gmail.com
> >>> > <mailto:ojayheggs at gmail.com>> wrote:
> >>> >
> >>> > Hi Hauke,
> >>> >
> >>> > I have actually reported an additional vulnerability since this email
> >>> >
> >>> > Subject: Security Vulnerability - OS command injection via unquoted
> >>> > shell pipe in luci-app-commands "Custom Commands" argument handling
> >>> > Sent on Friday the 31st of July
> >>> >
> >>> > Subject: Security Vulnerability - Remote Code Execution in DDNS
> >>> > (luci-app-ddns)
> >>> > Sent on Saturday the 8th of July, yesterday.
> >>> >
> >>> > Thank you for the reply,
> >>> > Oskar
> >>> >
> >>> > On Sun, 9 Aug 2026 at 17:12, Hauke Mehrtens <hauke at hauke-m.de
> >>> > <mailto:hauke at hauke-m.de>> wrote:
> >>> >
> >>> > On 7/31/26 20:50, OJ wrote:
> >>> > > Hello,
> >>> > >
> >>> > > I'm just writing to inform you that I have reported a critical
> >>> > > security vulnerability to the contact at openwrt.org
> >>> > <mailto:contact at openwrt.org> email. Due to the
> >>> > > critical nature I thought it was best to reach out to this public
> >>> > > mailing list.
> >>> > >
> >>> > > Kind regards,
> >>> > > Oskar
> >>> > >
> >>> > > _______________________________________________
> >>> > > openwrt-adm mailing list
> >>> > > openwrt-adm at lists.openwrt.org <mailto:openwrt-
> >>> > adm at lists.openwrt.org>
> >>> > > https://lists.openwrt.org/mailman/listinfo/openwrt-adm
> >>> > <https://lists.openwrt.org/mailman/listinfo/openwrt-adm>
> >>> >
> >>> > Hi Oskar,
> >>> >
> >>> > I can not find a mail from your mail address in the
> >>> > contact at openwrt.org <mailto:contact at openwrt.org>
> >>> > mailbox. When did you send it and what was the subject?
> >>> >
> >>> > Hauke
> >>> >
> >>>
>
> _______________________________________________
> openwrt-adm mailing list
> openwrt-adm at lists.openwrt.org
> https://lists.openwrt.org/mailman/listinfo/openwrt-adm
More information about the openwrt-adm
mailing list