Luci
by Openwrt
Source repositories
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-58000 | Hig | 0.00 | 8.8 | 0.03 | Jun 29, 2026 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN… | ||
| CVE-2023-24182 | Med | 0.00 | 5.4 | 0.01 | Apr 11, 2023 | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js. | ||
| CVE-2023-24181 | Med | 0.00 | 5.4 | 0.01 | Apr 10, 2023 | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm. | ||
| CVE-2022-41435 | Med | 0.00 | 5.4 | 0.01 | Nov 3, 2022 | OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments. | ||
| CVE-2019-25015 | Med | 0.00 | 5.4 | 0.01 | Jan 26, 2021 | LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID. |
- risk 0.00cvss 8.8epss 0.03
luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN…
- risk 0.00cvss 5.4epss 0.01
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.
- risk 0.00cvss 5.4epss 0.01
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.
- risk 0.00cvss 5.4epss 0.01
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
- risk 0.00cvss 5.4epss 0.01
LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
Page 2 of 2