Ttyd vulnerability

not allowed to create threads under security announcements...

users of ttyd (luci-app-docker) are advised this package opens unauthenticated root access via lan... mitigation involves reconfiguring to require login.

uci -q set ttyd.@ttyd[0].command='/bin/login'
uci commit ttyd
3 Likes

one month ( since reported... ) and still vulnerable...

@tsl0922

2 Likes

great to see this backdoor finally closed...

1 Like

This topic was automatically closed 10 days after the last reply. New replies are no longer allowed.