Skip to content
Threat Feed

Vendor

OpenWrt

7 briefs RSS
critical advisory

Authorization Bypass and RCE in luci-app-lxc

An ACL inconsistency in the OpenWrt luci-app-lxc package allows authenticated low-privileged users to achieve root code execution via path traversal and hook script manipulation.

luci-app-lxc
1r 2t 1c
critical advisory

Path Traversal in luci-app-openvpn via instance_name2 Parameter

An authenticated path traversal vulnerability in the luci-app-openvpn component of OpenWrt allows remote attackers to write arbitrary files to the filesystem and achieve persistent root-level code execution.

luci-app-openvpn path-traversal remote-code-execution openwrt network-security
2t 1c
high advisory

CVE-2026-69096: OS Command Injection in OpenWrt luci-app-dockerman

An authenticated OS command injection vulnerability in the docker_rpc.uc backend of luci-app-dockerman allows attackers with read-only ACLs to execute arbitrary commands as root via the /ubus RPC endpoint.

luci-app-dockerman
2t 1c
low advisory

CVE-2026-62184 - luci-app-banip Log Parsing Vulnerability

A log parsing vulnerability in OpenWrt's luci-app-banip allows an unauthenticated remote attacker to inject arbitrary IPv4 addresses into log lines via crafted input fields, leading to the misidentification and blocking of legitimate users or services while the true attacker remains unblocked.

luci-app-banip vulnerability log-parsing ip-spoofing openwrt
1c
high advisory

LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)

LuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.

PoC LuCI xss web-vulnerability network-device router dhcpv6
1t 1c updated
high advisory

CVE-2026-61875: Stored Cross-Site Scripting in OpenWrt luci-app-upnp

CVE-2026-61875 details a stored cross-site scripting vulnerability in OpenWrt's luci-app-upnp that allows unauthenticated LAN clients to inject malicious JavaScript into UPnP IGD AddPortMapping SOAP requests, leading to client-side code execution in an administrator's browser when viewing specific web interface pages.

luci-app-upnp cross-site-scripting xss openwrt router web-vulnerability client-side-execution
2t 1c
high advisory

OpenWrt luci-app-samba4 Vulnerability Allows Remote Command Execution

A vulnerability in OpenWrt's luci-app-samba4, identified as CVE-2026-59260, allows authenticated delegated users to achieve remote command execution on the Samba daemon by leveraging improper ACLs that grant `file.exec` permission on `/usr/sbin/smbd`.

luci-app-samba4 openwrt samba cve rce network linux
1r 2t 1c