Openwrt Luci vulnerabilities
17 known vulnerabilities affecting openwrt/luci.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH7MEDIUM7
Vulnerabilities
Page 1 of 1
CVE-2026-69096P2HIGHCVSS 8.8v26.162.29621~507ab5e2026-08-03
CVE-2026-69096 [HIGH] CWE-78 CVE-2026-69096: OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL grants broad ubus access to docker.* / docker.container.*, which exposes the docker.container.ttyd_start method even though it performs m
nvd
CVE-2026-72841P2CRITICALCVSS 9.9fixed in 24.10.7≥ 25.12.0, < 25.12.42026-08-13
CVE-2026-72841 [CRITICAL] CWE-73 CVE-2026-72841: luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowin
luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal and write arbitrary files outside the intended directory. Attackers can upload malicious payloads to gain persistent root code execution by placing SSH keys in system directories accessible on reboot.
nvd
CVE-2026-72842P2CRITICALCVSS 9.9≤ 24.10.8≥ 25.12.0, ≤ 25.12.52026-08-13
CVE-2026-72842 [CRITICAL] CWE-73 CVE-2026-72842: luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated Lu
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path traversal via `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `l
nvd
CVE-2026-59260P2HIGHCVSS 8.8fixed in 24.10.8≥ 25.12.0, < 25.12.52026-07-12
CVE-2026-59260 [HIGH] CWE-269 CVE-2026-59260: OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticat
OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments. Attackers can pass arbitrary Samba global options such as message command to a root smbd process, triggering command execution when SMB protocol messages are p
nvd
CVE-2026-55897P2HIGHCVSS 8.8fixed in 1.1.2-62026-09-21
CVE-2026-55897 [HIGH] CWE-78 CVE-2026-55897: luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to r
luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the luci-app-advanced-reboot read ACL in applications/luci-app-advanced-reboot/root/usr/share/rpcd/acl.d/luci-app-advanced-reb
nvd
CVE-2026-72840P3HIGHCVSS 8.8≤ 24.10.8≥ 25.12.0, ≤ 25.12.52026-08-13
CVE-2026-72840 [HIGH] CWE-266 CVE-2026-72840: OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants writ
OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL group can append arbitrary cron entries via ubus file.write, which the default busybox crond daemon executes as root
nvd
CVE-2019-12272P3CRITICALCVSS 9.8≤ 0.10.02019-05-23
CVE-2019-12272 [CRITICAL] CWE-78 CVE-2019-12272: In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
nvd
CVE-2026-69095P3HIGHCVSS 7.5fixed in 5890760a454dad2cb00389dba2cdc5e779e0ffdd2026-08-03
CVE-2026-69095 [HIGH] CWE-22 CVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path travers
OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that allows unauthenticated attackers to read files outside the configured runtimeDir. Attackers can supply directory traversal sequences in the query string to escape the intended directory and read sensitive
nvd
CVE-2026-61875P3HIGHCVSS 8.8fixed in 24.10.8≥ 25.12.0, < 25.12.52026-07-12
CVE-2026-61875 [HIGH] CWE-79 CVE-2026-61875: luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN c
luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding, executing the payload when administ
nvd
CVE-2026-67352P3HIGHCVSS 7.6fixed in *2026-08-01
CVE-2026-67352 [HIGH] CWE-79 CVE-2026-67352: luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url pa
luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTML. When an administrator views the HTTPS DNS Proxy status page, the resolver URL is rendered as raw HTML and executes JavaScript in the administrator's browser origin.
nvd
CVE-2026-62381P4MEDIUMCVSS 6.6≤ 42d72f79cd8f057f241595abc761b39dab2d9f072026-08-22
CVE-2026-62381 [MEDIUM] CWE-122 CVE-2026-62381: luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING allocation is computed from the DER length encoding of 255 bytes, but the payload written after prepending the unused-bits byte is 256
nvd
CVE-2020-10871P4MEDIUMCVSS 5.3vgit-20.049.11521-bebfe20vgit-20.078.22902-0ed0d422020-03-23
CVE-2020-10871 [MEDIUM] CWE-200 CVE-2020-10871: In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packag
In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no plan to restrict the information f
nvd
CVE-2026-68583P4MEDIUMCVSS 5.4fixed in 1.2.4-42026-08-02
CVE-2026-68583 [MEDIUM] CWE-79 CVE-2026-68583: luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blo
luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged users to inject active HTML. When an administrator views the AdBlock Fast status page, the injected payload executes in the administrator's browser under the LuCI origin.
nvd
CVE-2021-27821P4MEDIUMCVSS 6.1≤ 19.07.02021-05-25
CVE-2021-27821 [MEDIUM] CWE-79 CVE-2021-27821: The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site
The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.
nvd
CVE-2026-32721P4MEDIUMCVSS 4.8fixed in 26.072.65753-068150bfixed in 26.072.65753~068150b2026-03-19
CVE-2026-32721 [MEDIUM] CWE-79 CVE-2026-32721: LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a s
LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template literal to dom.append(), which p
nvd
CVE-2022-41435P4MEDIUMCVSS 5.4vgit-22.140.66206-02913be2022-11-03
CVE-2022-41435 [MEDIUM] CWE-79 CVE-2022-41435: OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scriptin
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.
nvd
CVE-2023-24181P4MEDIUMCVSS 5.4v22.03.32023-04-10
CVE-2023-24181 [MEDIUM] CWE-79 CVE-2023-24181: LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.
nvd