Insecure permissions in the script /etc/init.d/lighttpd...
High severity
Unreviewed
Published
Aug 1, 2025
to the GitHub Advisory Database
•
Updated Aug 4, 2025
Description
Published by the National Vulnerability Database
Aug 1, 2025
Published to the GitHub Advisory Database
Aug 1, 2025
Last updated
Aug 4, 2025
Insecure permissions in the script /etc/init.d/lighttpd in AK-Nord USB-Server-LXL Firmware v0.0.16 Build 2023-03-13 allows a locally authenticated low-privilege user to execute arbitrary commands with root privilege via editing this script which is executed with root-privileges on any interaction and on every system boot.
References