
CVE-2026-58000 luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is i… https://www.cve.org/CVERecord?id=CVE-2026-58000
Post summary
The announcement notes that CVE‑2026‑58000, a command injection flaw in luci-proto-openvpn’s generateKey method, has been fixed in commit e4ff45e, but no PoC, exploit, or active exploitation evidence is provided.

