VYPR

luci-app-upnp

by Openwrt

CVEs (1)

  • CVE-2026-61875Jul 12, 2026
    risk 0.00cvss epss 0.00

    luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and…