CVE Explorer
CVE-2026-30874
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject an arbitrary PATH variable, potentially leading to privilege escalation. The function is intended to filter out sensitive environment variables like PATH when executing hotplug scripts in /etc/hotplug.d, but a bug using strcmp instead of strncmp causes the filter to compare the ful
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 3 assertions
{"cweId":"CWE-74","description":"CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-187","description":"CWE-187: Partial String Comparison","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"openwrt","vendor":"openwrt","versions":[{"status":"affected","version":"< 24.10.6"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"LOCAL","baseScore":1.8,"baseSeverity":"LOW","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
3 source assertions{"cweId":"CWE-74","description":"CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-269","description":"CWE-269: Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/problemTypes/2/descriptions/0
{"cweId":"CWE-187","description":"CWE-187: Partial String Comparison","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/openwrt/openwrt/security/advisories/GHSA-jw28-hxcm-j934","tags":["x_refsource_CONFIRM"],"url":"https://github.com/openwrt/openwrt/security/advisories/GHSA-jw28-hxcm-j934"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/references/0
{"name":"https://github.com/openwrt/procd/commit/e08cdc8562f55b9ac228a21f3f7605a18c522b81","tags":["x_refsource_MISC"],"url":"https://github.com/openwrt/procd/commit/e08cdc8562f55b9ac228a21f3f7605a18c522b81"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:34700ac3ec73ac40a1482e6416b819f23a06f9d3bb41a8fb0f8da1144a135685 · sha256:1c078ddede26e34d… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.