Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

luci — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in luci, with AI-generated Chinese analysis, references, and POCs.

Vendor: X-WRT

CVE ID Title CVSS Severity Published
CVE-2026-55897 luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root CWE-78 8.8 High 2026-09-21
CVE-2026-62381 luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow CWE-122 6.6 Medium 2026-08-22
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass CWE-73 9.9 Critical 2026-08-13
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 CWE-73 9.9 Critical 2026-08-13
CVE-2026-72840 OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write CWE-266 8.8 High 2026-08-13
CVE-2026-69096 OpenWrt luci-app-dockerman Read ACL Remote Code Execution CWE-78 8.8 High 2026-08-03
CVE-2026-69095 OpenWrt luci-app-bmx7 Path Traversal via bmx7-info CWE-22 7.5 High 2026-08-03
CVE-2026-68583 luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name CWE-79 5.4 Medium 2026-08-02
CVE-2026-67352 luci-app-https-dns-proxy Stored XSS via resolver_url CWE-79 7.6 High 2026-08-01
CVE-2026-61876 LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting CWE-79 8.8 High 2026-07-12
CVE-2026-61875 luci-app-upnp Stored XSS via UPnP Port Mapping Description CWE-79 8.8 High 2026-07-12
CVE-2026-59260 OpenWrt luci-app-samba4 read ACL remote code execution via smbd CWE-269 8.8 High 2026-07-12
CVE-2026-32721 LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal CWE-79 8.6 High 2026-03-19
CVE-2023-3085 X-WRT luci 404 Error Template dispatcher.uc run_action cross site scripting CWE-79 3.5 Low 2023-06-03

All 14 known CVE vulnerabilities affecting luci with full Chinese analysis, references, and POCs where available.