Openwrt

Luci

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.42%
  • Veröffentlicht 13.08.2026 21:54:41
  • Zuletzt bearbeitet 14.08.2026 17:20:31

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `l...

  • EPSS 0.42%
  • Veröffentlicht 13.08.2026 21:54:40
  • Zuletzt bearbeitet 18.08.2026 02:17:28

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to g...

  • EPSS 0.3%
  • Veröffentlicht 13.08.2026 21:54:39
  • Zuletzt bearbeitet 14.08.2026 19:17:59

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can app...

  • EPSS 1.67%
  • Veröffentlicht 03.08.2026 13:20:48
  • Zuletzt bearbeitet 05.08.2026 05:17:13

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docke...

  • EPSS 0.62%
  • Veröffentlicht 03.08.2026 13:20:47
  • Zuletzt bearbeitet 03.08.2026 15:16:21

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supp...

  • EPSS 0.14%
  • Veröffentlicht 02.08.2026 12:15:29
  • Zuletzt bearbeitet 03.08.2026 17:16:44

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected pay...

  • EPSS 0.21%
  • Veröffentlicht 01.08.2026 12:22:16
  • Zuletzt bearbeitet 03.08.2026 17:16:42

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is render...

  • EPSS 0.45%
  • Veröffentlicht 13.07.2026 21:30:09
  • Zuletzt bearbeitet 15.07.2026 21:02:41

luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An u...

  • EPSS 0.29%
  • Veröffentlicht 12.07.2026 12:16:46
  • Zuletzt bearbeitet 13.07.2026 19:28:49

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which...

  • EPSS 0.85%
  • Veröffentlicht 12.07.2026 12:16:46
  • Zuletzt bearbeitet 14.07.2026 15:17:09

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrato...