High severity8.8NVD Advisory· Published Jul 12, 2026· Updated Jul 14, 2026
CVE-2026-61876
CVE-2026-61876
Description
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.