CVE Record
[ CRITICAL ]CVE-2026-72841
OpenWrt LuCI OpenVPN App Path Traversal Enables Root RCE
luci-app-openvpn path traversal on file upload enables persistent root code execution on OpenWrt routers by writing arbitrary files to system paths. CVSS 9.9 critical.
- Vendor
- OpenWrt
- Product
- LuCI (luci-app-openvpn)
- CVSS
- 9.9
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
luci-app-openvpn in OpenWrt’s LuCI interface fails to validate the instance_name2 parameter during file upload. Authenticated users can supply traversal sequences to write arbitrary files outside the intended directory — including to system paths that persist across reboots, enabling persistent root-level access.
Affected: OpenWrt installations running luci-app-openvpn
Patch: Fix tracked in the upstream OpenWrt LuCI repository. Remove luci-app-openvpn if not in use.
Source: GHSA-jjcx-c284-2qv8
