VYPR
Vendor

Openwrt

Products
31
CVEs
167
Across products
201
Status
Private

Products

31
View all 31 products →

Recent CVEs

167
View all 167 CVEs →
  • CVE-2024-20017CriMar 4, 2024
    risk 0.67cvss 9.8epss 0.46

    In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.

  • CVE-2026-72842CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.00

    luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape…

  • CVE-2026-72841CriAug 13, 2026
    risk 0.64cvss 9.9epss 0.00

    luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code…

  • CVE-2025-20683CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416938; Issue ID: MSV-3444.

  • CVE-2025-20682CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416937; Issue ID: MSV-3445.

  • CVE-2025-20681CriJul 8, 2025
    risk 0.64cvss 9.8epss 0.01

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416936; Issue ID: MSV-3446.

  • CVE-2025-20674CriJun 2, 2025
    risk 0.64cvss 9.8epss 0.01

    In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202;…

  • CVE-2025-20654CriApr 7, 2025
    risk 0.64cvss 9.8epss 0.01

    In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

  • CVE-2020-28951CriNov 19, 2020
    risk 0.64cvss 9.8epss 0.02

    libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.

  • CVE-2020-11967CriApr 21, 2020
    risk 0.64cvss 9.8epss 0.03

    In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial…

  • CVE-2026-46368HigMay 26, 2026
    risk 0.61cvss 8.8epss 0.07

    luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An…

  • CVE-2026-72840HigAug 13, 2026
    risk 0.57cvss 8.8epss 0.00

    OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries…

  • CVE-2026-30872CriMar 19, 2026
    risk 0.57cvss 9.8epss 0.02

    OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS…

  • CVE-2026-30871CriMar 19, 2026
    risk 0.57cvss 9.8epss 0.01

    OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains…

  • CVE-2026-20430HigMar 2, 2026
    risk 0.57cvss 8.8epss 0.00

    In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2026-20408HigFeb 2, 2026
    risk 0.57cvss 8.8epss 0.00

    In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461651; Issue…

  • CVE-2025-20720HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2025-20719HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2025-20712HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…

  • CVE-2025-20711HigOct 14, 2025
    risk 0.57cvss 8.8epss 0.00

    In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…