CVE-2024-51240
Severity CVSS v4.0:
Pending analysis
Type:
CWE-522
Insufficiently Protected Credentials
Publication date:
05/11/2024
Last modified:
06/11/2024
Description
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH