vciy

CVEs we hold for Openwrt

Records whose assigning authority named Openwrt as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-72842OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypassopenwrt luci
CVE-2026-72841luci-app-openvpn Path Traversal RCE via instance_name2openwrt luci
CVE-2026-72840OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Writeopenwrt luci
CVE-2026-69096OpenWrt luci-app-dockerman Read ACL Remote Code Executionopenwrt luci
CVE-2026-69095OpenWrt luci-app-bmx7 Path Traversal via bmx7-infoopenwrt luci
CVE-2026-68583luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.nameopenwrt luci
CVE-2026-67352luci-app-https-dns-proxy Stored XSS via resolver_urlopenwrt luci
CVE-2026-62948OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the…openwrt
CVE-2026-62947OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-downloadopenwrt
CVE-2026-62381luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflowopenwrt luci
CVE-2026-62184luci-app-banip Log Monitor IP Extraction Bypassopenwrt luci-app-banip
CVE-2026-61876LuCI DHCPv6 Lease Hostname Stored Cross-Site Scriptingopenwrt luci
CVE-2026-61875luci-app-upnp Stored XSS via UPnP Port Mapping Descriptionopenwrt luci
CVE-2026-59260OpenWrt luci-app-samba4 read ACL remote code execution via smbdopenwrt luci
CVE-2026-58652luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameteropenwrt travelmate
CVE-2026-58000luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKeyopenwrt luci-proto-openvpn
CVE-2026-57999luci-app-tailscale-community - Command Injection via tailscale.do_login RPCopenwrt luci-app-tailscale-community
CVE-2026-55490OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Serviceopenwrt
CVE-2026-32721LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modalopenwrt
CVE-2026-30874OpenWrt procd PATH Environment Variable Filter Bypass via Incorrect String Comparison Leads to Privilege Escalationopenwrt
CVE-2026-30873OpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokensopenwrt
CVE-2026-30872OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupopenwrt
CVE-2026-30871OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Queryopenwrt
CVE-2025-62526OpenWrt ubusd vulnerable to heap buffer overflowopenwrt
CVE-2025-62525OpenWrt vulnerable to local privilage escalationopenwrt
CVE-2024-54143openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionopenwrt asu
CVE-2019-5102no title heldOpenWRT
CVE-2019-5101no title heldOpenWRT

28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.