This if f*cking scary. Such a simple code, so dangerous and it works. You can trivially add an extra root user via /etc/{passwd|shadow}. There are tons of options how to p0wn a system.
Please update your devices ASAP!
Please update your devices ASAP!
Does it need patching? Of course. It’s not a privilege escalation remote code execution issue though, and even if it was, it would be on a tiny fraction of running devices right now.
That's correct and I misjudged the situation. Sorry!
Sorry!