Skip to main content

Vendor/product archive

openwrt / openwrt CVEs

Beta · best-effort

136 CVEs tagged to openwrt / openwrt10 Critical, 36 High, 86 Medium, 4 Low, 0 Unrated.

CVE-2026-62947

Published Jul 15, 2026

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus sessio…

CVSS 4.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-62948

Published Jul 15, 2026

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefi…

CVSS 9.6 · Critical
evidence mentions
5
Buzz score
22.9
Vendor/product tagsBeta · best-effort

CVE-2026-55490

Published Jul 7, 2026

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-32721

Published Mar 19, 2026

LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan…

CVSS 8.6 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-30874

Published Mar 19, 2026

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass env…

CVSS 1.8 · Low
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-30873

Published Mar 19, 2026

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, the jp_get_token function, which performs lexical analysis b…

CVSS 2.4 · Low
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-30872

Published Mar 19, 2026

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability i…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-30871

Published Mar 19, 2026

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability i…

CVSS 9.5 · Critical
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-20747

Published Nov 4, 2025

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtain…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20746

Published Nov 4, 2025

In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtain…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20742

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no addition…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-20741

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obta…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20739

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obta…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20738

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obta…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20737

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-20736

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obta…

CVSS 6.7 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20735

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-20734

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obta…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-20733

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-20732

Published Nov 4, 2025

In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obta…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 136 CVEsPage 1 of 6