CVE-2026-55897
- EPSS 0.46%
- Veröffentlicht 21.09.2026 19:29:37
- Zuletzt bearbeitet 24.09.2026 21:25:27
luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanc...
CVE-2026-62381
- EPSS 0.08%
- Veröffentlicht 22.08.2026 13:16:39
- Zuletzt bearbeitet 24.09.2026 20:43:32
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DE...
CVE-2026-72842
- EPSS 0.42%
- Veröffentlicht 13.08.2026 21:54:41
- Zuletzt bearbeitet 30.09.2026 18:18:39
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `l...
CVE-2026-72841
- EPSS 0.42%
- Veröffentlicht 13.08.2026 21:54:40
- Zuletzt bearbeitet 30.09.2026 18:18:39
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to g...
CVE-2026-72840
- EPSS 0.3%
- Veröffentlicht 13.08.2026 21:54:39
- Zuletzt bearbeitet 30.09.2026 18:18:39
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can app...
CVE-2026-69096
- EPSS 1.67%
- Veröffentlicht 03.08.2026 13:20:48
- Zuletzt bearbeitet 09.09.2026 20:35:08
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docke...
CVE-2026-69095
- EPSS 0.62%
- Veröffentlicht 03.08.2026 13:20:47
- Zuletzt bearbeitet 09.09.2026 20:35:08
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supp...
CVE-2026-68583
- EPSS 0.14%
- Veröffentlicht 02.08.2026 12:15:29
- Zuletzt bearbeitet 09.09.2026 20:35:08
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected pay...
CVE-2026-67352
- EPSS 0.21%
- Veröffentlicht 01.08.2026 12:22:16
- Zuletzt bearbeitet 08.09.2026 20:35:01
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is render...
CVE-2026-62184
- EPSS 0.45%
- Veröffentlicht 13.07.2026 21:30:09
- Zuletzt bearbeitet 15.07.2026 21:02:41
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An u...