Skip to content

Fix command injection in SSID and OpenVPN cfg_id handling - #2161

Merged
billz merged 1 commit into
masterfrom
fix/cmd-injections
Oct 2, 2026
Merged

billz merged 1 commit into
masterfrom
fix/cmd-injections

Conversation

@billz

@billz billz commented Oct 2, 2026

Copy link
Copy Markdown
Member

CVE-2026-101858: WiFiManager::writeWpaSupplicant() called escapeshellarg() before ssid2utf8(), so an SSID containing \x27 was decoded into a literal quote after escaping. That broke out of the quoting and allowed commands to run as www-data. The SSID is now decoded first and escaped second.

CVE-2026-101859: del_ovpncfg.php passed $POST['cfg_id'] through escapeshellcmd() into "sudo rm", which allowed path traversal and deletion of arbitrary files as root. cfg_id is now validated against /^[A-Za-z0-9-][A-Za-z0-9.-]*$/D. Instead of an *.conf glob, only _client.conf and _login.conf are removed, with each path quoted. The glob also deleted unrelated configs with a matching prefix (e.g. deleting "foo" also removed "foo_bar").

activate_ovpncfg.php had the same cfg_id pattern feeding "sudo ln -s" and gets the same validation and quoting.

Invalid ids now return HTTP 400 with a JSON body.

CVE-2026-101858: WiFiManager::writeWpaSupplicant() called
escapeshellarg() before ssid2utf8(), so an SSID containing \x27 was
decoded into a literal quote after escaping. That broke out of the
quoting and allowed commands to run as www-data. The SSID is now
decoded first and escaped second.

CVE-2026-101859: del_ovpncfg.php passed $_POST['cfg_id'] through
escapeshellcmd() into "sudo rm", which allowed path traversal and
deletion of arbitrary files as root. cfg_id is now validated against
/^[A-Za-z0-9_-][A-Za-z0-9._-]*$/D. Instead of an _*.conf glob, only
_client.conf and _login.conf are removed, with each path
quoted. The glob also deleted unrelated configs with a matching prefix
(e.g. deleting "foo" also removed "foo_bar").

activate_ovpncfg.php had the same cfg_id pattern feeding "sudo ln -s"
and gets the same validation and quoting.

Invalid ids now return HTTP 400 with a JSON body.

Co-Authored-By: Claude Opus 5.5 
@billz
billz merged commit f5dee82 into master Oct 2, 2026
3 checks passed
@billz
billz deleted the fix/cmd-injections branch October 2, 2026 01:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant