CVEs we hold for Openwrt
Records whose assigning authority named Openwrt as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-62948OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the…openwrt
CVE-2026-58652luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameteropenwrt travelmate
CVE-2026-58000luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKeyopenwrt luci-proto-openvpn
CVE-2026-57999luci-app-tailscale-community - Command Injection via tailscale.do_login RPCopenwrt luci-app-tailscale-community
CVE-2026-32721LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modalopenwrt
CVE-2026-30874OpenWrt procd PATH Environment Variable Filter Bypass via Incorrect String Comparison Leads to Privilege Escalationopenwrt
CVE-2026-30873OpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokensopenwrt
CVE-2026-30872OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupopenwrt
CVE-2024-54143openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionopenwrt asu
28 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.