OpenWRT luci是OpenWRT社区开源的一款路由器配置界面。 OpenWRT luci存在跨站脚本漏洞,该漏洞源于在状态表中呈现DHCPv6租约主机名前未能正确编码,导致相邻网络攻击者注入HTML标记。攻击者可以通过发送包含脚本标签的DHCPv6 Client FQDN,在管理员查看DHCP租约页面时执行脚本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-59260 | 8.8 HIGH | OpenWrt luci-app-samba4 read ACL remote code execution via smbd |
| CVE-2026-61875 | 8.8 HIGH | luci-app-upnp Stored XSS via UPnP Port Mapping Description |
No comments yet