Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-62184— luci-app-banip Log Monitor IP Extraction Bypass

CVSS 7.5 · High EPSS 0.45% · P37

Possible ATT&CK Techniques 1AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 2

VendorProductVersion RangeStatus
openwrtluci-app-banip≤ 0.11.1affected
d9bbc372e29618a8807b693a1ccf6d0e42cd196cunaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-62184

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
luci-app-banip Log Monitor IP Extraction Bypass
Source: CVE Program / CVE List V5
Vulnerability Description
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the login username field, causing banIP to block the wrong target while the real attacker remains unblocked.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对输出编码和转义不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
OpenWRT luci 输出处理不当漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
OpenWRT luci是OpenWRT社区开源的一款路由器配置界面。 OpenWRT luci 0.11.1及之前版本存在输出处理不当漏洞,该漏洞源于luci-app-banip的awk解析器从日志行中提取第一个IPv4地址,无论字段位置如何,允许攻击者通过攻击者控制的字段(如用户名)注入任意IP地址,可能导致未经身份验证的远程攻击者在登录用户名字段注入IP地址,导致banIP拦截错误目标。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
openwrtluci-app-banip 0 ~ 0.11.1 -

II. Public POCs for CVE-2026-62184

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium
Qwen3.6-35B-A3B · 9171 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-62184

登录查看更多情报信息。

Vendor Advisories for CVE-2026-62184 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-62184

No comments yet


Leave a comment