CVE-2026-72842
- EPSS 0.42%
- Veröffentlicht 13.08.2026 21:54:41
- Zuletzt bearbeitet 14.08.2026 17:20:31
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `l...
CVE-2026-72841
- EPSS 0.42%
- Veröffentlicht 13.08.2026 21:54:40
- Zuletzt bearbeitet 18.08.2026 02:17:28
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to g...
CVE-2026-72840
- EPSS 0.3%
- Veröffentlicht 13.08.2026 21:54:39
- Zuletzt bearbeitet 14.08.2026 19:17:59
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can app...
CVE-2026-69096
- EPSS 1.67%
- Veröffentlicht 03.08.2026 13:20:48
- Zuletzt bearbeitet 05.08.2026 05:17:13
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docke...
CVE-2026-69095
- EPSS 0.62%
- Veröffentlicht 03.08.2026 13:20:47
- Zuletzt bearbeitet 03.08.2026 15:16:21
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supp...
CVE-2026-68583
- EPSS 0.14%
- Veröffentlicht 02.08.2026 12:15:29
- Zuletzt bearbeitet 03.08.2026 17:16:44
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected pay...
CVE-2026-67352
- EPSS 0.21%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 03.08.2026 17:16:42
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is render...
CVE-2026-62184
- EPSS 0.45%
- Veröffentlicht 13.07.2026 21:30:09
- Zuletzt bearbeitet 15.07.2026 21:02:41
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An u...
CVE-2026-61875
- EPSS 0.29%
- Veröffentlicht 12.07.2026 12:16:46
- Zuletzt bearbeitet 13.07.2026 19:28:49
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which...
CVE-2026-61876
- EPSS 0.85%
- Veröffentlicht 12.07.2026 12:16:46
- Zuletzt bearbeitet 14.07.2026 15:17:09
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrato...