VYPR

Vendor CVEs

Openwrt

All CVEs

171 total · sorted by risk
  • CVE-2019-12272CriMay 23, 2019
    risk 0.01cvss 9.8epss 0.10

    In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

  • CVE-2026-62947MedJul 15, 2026
    risk 0.00cvss 4.9epss 0.01

    OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and rpcd session.c uses fnmatch() without FNM_PATHNAME, allowing…

  • CVE-2026-62948CriJul 15, 2026
    risk 0.00cvss 9.6epss 0.01

    OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline…

  • CVE-2026-62184HigJul 13, 2026
    risk 0.00cvss 7.5epss 0.01

    luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote…

  • CVE-2026-61876HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.01

    LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP…

  • CVE-2026-61875HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.01

    luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and…

  • CVE-2026-59260HigJul 12, 2026
    risk 0.00cvss 8.8epss 0.01

    OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root…

  • CVE-2026-55490MedJul 7, 2026
    risk 0.00cvss 6.5epss 0.01

    OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The…

  • CVE-2026-58000HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.03

    luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escaping or quoting. An authenticated LuCI user with OpenVPN…

  • CVE-2026-57999HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.02

    luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-controlled loginserver and loginserver_authkey parameters are…

  • CVE-2025-62526HigOct 22, 2025
    risk 0.00cvss 7.9epss 0.00

    OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the…

  • CVE-2025-62525HigOct 22, 2025
    risk 0.00cvss 7.9epss 0.00

    OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the datapath of the DSL line. This only effects the lantiq…

  • CVE-2023-38322HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…

  • CVE-2023-38320HigNov 17, 2023
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service…

  • CVE-2023-38316CriNov 17, 2023
    risk 0.00cvss 9.8epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2…

  • CVE-2023-38314MedNov 17, 2023
    risk 0.00cvss 6.5epss 0.01

    An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing…

  • CVE-2023-24182MedApr 11, 2023
    risk 0.00cvss 5.4epss 0.01

    LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.

  • CVE-2023-24181MedApr 10, 2023
    risk 0.00cvss 5.4epss 0.01

    LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.

  • CVE-2022-41435MedNov 3, 2022
    risk 0.00cvss 5.4epss 0.01

    OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.

  • CVE-2021-28961HigMar 21, 2021
    risk 0.00cvss 8.8epss 0.02

    applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.

  • CVE-2019-25015MedJan 26, 2021
    risk 0.00cvss 5.4epss 0.01

    LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.

Page 4 of 4