VYPR

Luci

by Openwrt

Source repositories

CVEs (25)

  • CVE-2026-72842CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.01

    luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape…

  • CVE-2026-72841CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.01

    luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code…

  • CVE-2026-72840HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries…

  • CVE-2026-55897HigSep 21, 2026
    risk 0.50cvss 8.8epss 0.01

    luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in…

  • CVE-2026-55159HigSep 21, 2026
    risk 0.50cvss 8.8epss 0.00

    luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carriage-return or line-feed characters and…

  • CVE-2019-17367HigOct 18, 2019
    risk 0.50cvss 8.8epss 0.01

    OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.

  • CVE-2026-69095HigAug 3, 2026
    risk 0.49cvss 7.5epss 0.01

    OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal…

  • CVE-2026-67352HigAug 1, 2026
    risk 0.49cvss 7.6epss 0.00

    luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes…

  • CVE-2026-32721HigMar 19, 2026
    risk 0.49cvss 8.6epss 0.00

    LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the…

  • CVE-2026-62381MedAug 22, 2026
    risk 0.43cvss 6.6epss 0.00

    luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255…

  • CVE-2021-27821MedMay 25, 2021
    risk 0.40cvss 6.1epss 0.01

    The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.

  • CVE-2026-68583MedAug 2, 2026
    risk 0.35cvss 5.4epss 0.00

    luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the…

  • CVE-2025-57389MedOct 1, 2025
    risk 0.35cvss 5.4epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. This vulnerability was fixed in OpenWRT v19.07.0.

  • CVE-2021-33425MedMay 25, 2021
    risk 0.35cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.

  • CVE-2020-10871MedMar 23, 2020
    risk 0.35cvss 5.3epss 0.02

    In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other…

  • CVE-2019-18993MedDec 3, 2019
    risk 0.28cvss 5.4epss 0.01

    OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).

  • CVE-2019-18992MedDec 3, 2019
    risk 0.28cvss 5.4epss 0.01

    OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).

  • CVE-2019-12272CriMay 23, 2019
    risk 0.01cvss 9.8epss 0.07

    In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

  • CVE-2026-62184HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote…

  • CVE-2026-61876HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.01

    LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP…

Page 1 of 2