PatchSiren

openwrt CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH openwrt CVE published 2026-09-21

CVE-2026-55159

CVE-2026-55159 is a high-severity vulnerability in the luci-app-adblock-fast WebUI for OpenWrt, which allows an authenticated delegated user with the write ACL to create a persistent command execution as UID 0 when cron runs. The issue is fixed in version 1.2.4-2. This vulnerability impacts OpenWrt systems with luci-app-adblock-fast installed, allowing attackers to execute commands with elevated privilege [truncated]

MEDIUM openwrt CVE published 2026-08-22

CVE-2026-62381

A heap-based buffer overflow exists in luci-lib-px5g's ASN.1 encoding routine when signing certificates with 2040-bit RSA keys. The vulnerability is reachable via the Lua interface and may be remotely exploitable depending on the application. It affects OpenWRT versions from openwrt-18.06 to openwrt-25.12. OpenWRT administrators and developers should assess their exposure and prioritize patching, especial [truncated]

CRITICAL openwrt CVE published 2026-08-13

CVE-2026-72842

CVE-2026-72842 debrief: LuCI users with low privileges can access unauthorized container management routes due to an ACL inconsistency in luci-app-lxc, allowing potential root code execution via path traversal. This vulnerability can be exploited through path traversal using `/.%2E` in the `lxc_name` parameter to escape container directories and control host-side scripts executed through `lxc.hook.start-h [truncated]

CRITICAL openwrt CVE published 2026-08-13

CVE-2026-72841

CVE-2026-72841 debrief based on the supplied source corpus. The CVE record was published on 2026-08-13T22:17:23.813Z and has not been modified since then. The NVD entry is currently Deferred. This critical vulnerability in luci-app-openvpn allows authenticated users to perform path traversal and write arbitrary files outside the intended directory, potentially leading to persistent root code execution. Sy [truncated]

HIGH openwrt CVE published 2026-08-13

CVE-2026-72840

Authenticated users with mount-configuration ACL group can append arbitrary cron entries via ubus file.write, executed as root within one minute. This overly permissive ACL definition in luci-mod-system-mounts grants write access to /etc/crontabs/root to users intended only for mount configuration, potentially leading to unauthorized code execution as root. The default busybox crond daemon executes cron e [truncated]

HIGH openwrt CVE published 2026-08-03

CVE-2026-69096

The OpenWrt luci-app-dockerman package contains an OS command injection vulnerability due to broad ubus access granted by the package's read ACL. The vulnerability allows authenticated attackers to inject shell metacharacters and execute arbitrary commands as root via an HTTP POST to /ubus. This issue affects OpenWrt master and openwrt-25.12 snapshots with the ucode docker_rpc.uc RPC backend after the JS/ [truncated]

HIGH openwrt CVE published 2026-08-03

CVE-2026-69095

CVE-2026-69095 is a high-severity path traversal vulnerability in OpenWrt luci-app-bmx7 that allows unauthenticated attackers to read sensitive files outside the configured runtimeDir. The vulnerability exists in the bmx7-info CGI script and can be exploited by supplying directory traversal sequences in the query string. Defenders should assess exposure and prioritize patching to prevent potential unautho [truncated]

MEDIUM openwrt CVE published 2026-08-02

CVE-2026-68583

The luci-app-adblock-fast package before version 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field. This allows lower-privileged users to inject active HTML, which executes in the administrator's browser when viewing the AdBlock Fast status page. The vulnerability has a CVSS score of 5.1 and a severity rating of MEDIUM. To address this vulnerability, organizations sh [truncated]

MEDIUM openwrt CVE published 2026-08-01

CVE-2026-67352

The luci-app-https-dns-proxy package contains a stored cross-site scripting vulnerability in the resolver_url parameter. Authenticated users can inject active HTML, which is rendered as raw HTML and executes JavaScript in the administrator's browser origin when the HTTPS DNS Proxy status page is viewed. The vulnerability has a CVSS score of 6.8 and a severity of MEDIUM. The CVE record was published on 202 [truncated]

MEDIUM openwrt CVE published 2026-07-15

CVE-2026-62947

The cgi-download handler in OpenWrt's cgi-io package is vulnerable to path traversal attacks, allowing access to root-readable files. The vulnerability is fixed in OpenWrt version 25.12.5. Users should update to the latest version and review their systems for potential exposure. The issue arises from authorizing requested paths against the caller's ubus session file ACL before canonicalization, and the us [truncated]

CRITICAL openwrt CVE published 2026-07-15

CVE-2026-62948

OpenWrt, a Linux operating system for embedded devices, is vulnerable to a critical issue (CVSS Score: 9.6) allowing DHCPv6 client FQDN option 39 hostname injection. Prior to version 25.12.5, odhcpd writes unsanitized hostnames into /tmp/odhcpd.leases, enabling attackers to inject forged lease lines. This issue is fixed in version 25.12.5. The vulnerability exists in the odhcpd component of OpenWrt, speci [truncated]

HIGH openwrt CVE published 2026-07-13

CVE-2026-62184

CVE-2026-62184 luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the login username field, causing banIP to block the wrong target while the real a [truncated]

CRITICAL openwrt CVE published 2026-07-12

CVE-2026-61876

The CVE record indicates that LuCI versions have a vulnerability where DHCPv6 lease hostnames are not properly encoded before being rendered in status tables. This allows adjacent network attackers to inject HTML markup by sending a DHCPv6 Client FQDN containing script tags. These script tags can execute in the administrator's browser when viewing DHCP lease pages. The vulnerability is critical, with a CV [truncated]

HIGH openwrt CVE published 2026-07-12

CVE-2026-61875

CVE-2026-61875 is a stored cross-site scripting vulnerability in luci-app-upnp. Unauthenticated LAN clients can inject JavaScript via UPnP IGD AddPortMapping SOAP requests by sending malicious HTML in the NewPortMappingDescription field. The payload executes when administrators view the UPnP or Status pages. This vulnerability has a high CVSS score of 8.7 and is considered a high-severity issue. Administr [truncated]

HIGH openwrt CVE published 2026-07-12

CVE-2026-59260

The OpenWrt luci-app-samba4 vulnerability allows authenticated delegated users to execute the Samba daemon with caller-controlled command-line arguments due to a read ACL granting file.exec permission on /usr/sbin/smbd. This enables attackers to pass arbitrary Samba global options, such as message command, to a root smbd process, potentially triggering command execution when SMB protocol messages are proc [truncated]

MEDIUM openwrt CVE published 2026-07-07

CVE-2026-55490

CVE-2026-55490 is an integer underflow vulnerability in OpenWrt's Emergency Access Daemon. Before v25.12.5, an unauthenticated attacker on the local network can crash the daemon by sending a single crafted UDP packet. The message length underflows before a bounds check and is then passed to memcpy as a very large size. This issue is fixed in v25.12.5. The vulnerability has a CVSS score of 6.5 and is class [truncated]

HIGH openwrt CVE published 2026-07-02

CVE-2026-58652

The CVE-2026-58652 vulnerability in luci-app-travelmate allows for arbitrary command execution as root due to a privilege-escalation flaw. An attacker with delegated write permissions can exploit this by setting the 'script' UCI value to /bin/sh and 'script_args' to attacker-controlled arguments. This issue was confirmed in luci-app-travelmate/travelmate version 2.4.5-r3 and remains present in travelmate [truncated]