CVE-2026-30874General(openwrt / openwrt)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject an arbitrary PATH variable, potentially leading to privilege escalation. The function is intended to filter out sensitive environment variables like PATH when executing hotplug scripts in /etc/hotplug.d, but a bug using strcmp instead of strncmp causes the filter to compare the full environment string (e.g., PATH=/some/value) against the literal "PATH", so the match always fails. As a result, the PATH variable is never excluded, enabling an attacker to control which binaries are executed by procd-invoked scripts running with elevated privileges. This issue has been fixed in version 24.10.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-187CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openwrt

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
openwrt

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-20: 2Technical Details · 2026-03-20: 103-20
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    General

    CVE-2026-30874 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker … https://www.cve.org/CVERecord?id=CVE-2026-30874

    Post summary

    The text briefly mentions CVE-2026-30874 affecting OpenWrt prior to 24.10.6, noting a hotplug_call function vulnerability, but provides no further details on exploitation, patches, or technical specifics.

    00010251
    56.8K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-30874 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker … https://www.cve.org/CVERecord?id=CVE-2026-30874 ----- Traducción: CVE-2026-30874 Ope… http://infoflow.cloud`

    Post summary

    The tweet alerts to CVE-2026-30874, a vulnerability in OpenWrt’s hotplug_call function affecting versions before 24.10.6, but provides no PoC, exploit, patch, or active exploitation details.

    0000063
    61 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSopenwrtopenwrt---

Explore more