Tag
high
advisory
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)
1 TTP 1 CVELuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.
LuCI
xss
web-vulnerability
network-device
router
dhcpv6
1t
1c
critical
advisory
BusyBox DHCPv6 Client Heap Buffer Overflow Vulnerability (CVE-2026-29004)
2 rules 2 TTPs 1 CVEA heap buffer overflow vulnerability in BusyBox's DHCPv6 client allows network-adjacent attackers to trigger memory corruption, denial of service, or arbitrary code execution via crafted DHCPv6 responses.
BusyBox
heap-overflow
dhcpv6
cve-2026-29004
denial-of-service
2r
2t
1c