CVE-2026-78797
Received Received - Intake

Remote Code Execution in iStoreOS

Vulnerability report for CVE-2026-78797, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

An issue in iStoreOS istoreos-24.10.7 and before allows a remote attacker to execute arbitrary code via the task_id in tasks-lib.lua.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-10
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
n/a n/a n/a

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-78797 is a command injection vulnerability in iStoreOS versions istoreos-24.10.7 and earlier. It allows a remote attacker to execute arbitrary code via the task_id parameter in tasks-lib.lua. The flaw occurs because the application fails to properly validate user input before using it in system commands, enabling command splicing and remote code execution.

Detection Guidance

To detect this vulnerability, monitor network traffic for suspicious connections to the LuCI web interface at /cgi-bin/luci/admin/system/tasks/status. Check for unexpected reverse shell connections using netstat or ss commands like 'netstat -tulnp | grep nc' or 'ss -tulnp | grep nc'. Inspect logs for unauthorized login attempts or unusual task_id parameter usage in HTTP requests.

Impact Analysis

An attacker could exploit this to gain full control of the affected router. This includes executing arbitrary commands, installing malware, stealing data, or using the router as a pivot point to attack other devices on the network. The exploit can be performed remotely if the attacker has network access to the router's web interface.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security rules for protected health information. Organizations using affected routers may face compliance violations, legal penalties, and reputational damage due to potential data breaches.

Mitigation Strategies

Immediately update iStoreOS to the latest version beyond 24.10.7. Disable remote access to the LuCI interface if not required. Change default credentials and enforce strong passwords. Implement network segmentation to limit access to the router's management interface. Monitor for signs of compromise such as unexpected reverse shells or unauthorized commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78797. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart