Skip to main content

Vendor/product archive

openwrt / luci CVEs

Beta · best-effort

6 CVEs tagged to openwrt / luci1 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-32721

Published Mar 19, 2026

LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan…

CVSS 8.6 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2023-24181

Published Apr 10, 2023

LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-41435

Published Nov 3, 2022

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27821

Published May 25, 2021

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-10871

Published Mar 23, 2020

In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report beca…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-12272

Published May 23, 2019

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injec…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1