CVE-2026-58652 Details
Description
luci-app-travelmate (and the travelmate package) contain a privilege-escalation flaw: a LuCI/rpcd session holding the luci-app-travelmate write ACL is granted config-wide UCI write access to the travelmate configuration. While the LuCI UI restricts the auto-login script picker to /etc/travelmate/*.login, this is only a frontend restriction. The backend travelmate service (running as root) reads the raw UCI 'script' and 'script_args' values and executes the configured path when the captive-portal auto-login branch (f_check() in travelmate-functions.sh) is reached. An attacker with delegated write permissions can set script to /bin/sh and script_args to attacker-controlled arguments, resulting in arbitrary command execution as root. Confirmed in luci-app-travelmate/travelmate 2.4.5-r3; the sink is still present in travelmate 2.4.6-1 and no patched version is known.
A privilege escalation vulnerability has been identified in the OpenWrt LuCI Travelmate application, specifically in versions through 2.4.5-r3. The issue arises from a LuCI/rpcd session with delegated write permissions, which is granted config-wide UCI write access to the Travelmate configuration. While the LuCI user interface restricts the auto-login script selection to certain files, this limitation is not enforced in the backend. The Travelmate service, running with root privileges, executes the specified script and arguments when the auto-login feature is triggered, leading to arbitrary command execution as root.
Users can remove the 'luci-app-travelmate' write ACL from roles that should not have command execution capabilities. Additionally, the Travelmate package can be updated to version 2.4.6-1, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 2, 2026CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OpenWrt LuCI-app-travelmate | <= 2.4.5-r3 (semver) |
CPE
Remediation
| |
| OpenWrt travelmate | <= 2.4.5-r3 (semver) 2.4.6-1 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 28, 2026 | CVE Modified | [email protected] |
| Aug 28, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 2, 2026 | New CVE Received | [email protected] |
Volerion