VYPR

Luci

by Openwrt

Source repositories

CVEs (25)

  • CVE-2026-58000HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.03

    luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN…

  • CVE-2023-24182MedApr 11, 2023
    risk 0.00cvss 5.4epss 0.01

    LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.

  • CVE-2023-24181MedApr 10, 2023
    risk 0.00cvss 5.4epss 0.01

    LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.

  • CVE-2022-41435MedNov 3, 2022
    risk 0.00cvss 5.4epss 0.01

    OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

  • CVE-2019-25015MedJan 26, 2021
    risk 0.00cvss 5.4epss 0.01

    LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.

Page 2 of 2