Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

OpenWRT — Vulnerabilities & Security Advisories 28

Browse all 28 CVE security advisories affecting OpenWRT. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OpenWRT serves as a Linux-based firmware alternative for embedded networking devices, primarily used to extend router functionality and custom networking solutions. Historically, vulnerabilities have included remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from web interface components and default configurations. The project maintains a relatively low CVE count compared to commercial alternatives, with current vulnerabilities primarily affecting specific packages rather than the core system. While no major security incidents have been widely documented, the project's open nature allows for rapid vulnerability identification and patching, though users must remain vigilant with updates to mitigate risks associated with third-party package installations.

CVE ID Title CVSS Severity Published
CVE-2026-62381 luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow — luci CWE-122 6.6 Medium 2026-08-22
CVE-2026-72841 luci-app-openvpn Path Traversal RCE via instance_name2 — luci CWE-73 9.9 Critical 2026-08-13
CVE-2026-72842 OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass — luci CWE-73 9.9 Critical 2026-08-13
CVE-2026-72840 OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write — luci CWE-266 8.8 High 2026-08-13
CVE-2026-69096 OpenWrt luci-app-dockerman Read ACL Remote Code Execution — luci CWE-78 8.8 High 2026-08-03
CVE-2026-69095 OpenWrt luci-app-bmx7 Path Traversal via bmx7-info — luci CWE-22 7.5 High 2026-08-03
CVE-2026-68583 luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name — luci CWE-79 5.4 Medium 2026-08-02
CVE-2026-67352 luci-app-https-dns-proxy Stored XSS via resolver_url — luci CWE-79 7.6 High 2026-08-01
CVE-2026-62947 OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download — openwrt CWE-22 4.9 Medium 2026-07-15
CVE-2026-62948 OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI — openwrt CWE-79 9.6 Critical 2026-07-15
CVE-2026-62184 luci-app-banip Log Monitor IP Extraction Bypass — luci-app-banip CWE-116 7.5 High 2026-07-13
CVE-2026-61876 LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting — luci CWE-79 8.8 High 2026-07-12
CVE-2026-61875 luci-app-upnp Stored XSS via UPnP Port Mapping Description — luci CWE-79 8.8 High 2026-07-12
CVE-2026-59260 OpenWrt luci-app-samba4 read ACL remote code execution via smbd — luci CWE-269 8.8 High 2026-07-12
CVE-2026-55490 OpenWrt: EAD Integer Underflow → Pre-Auth Denial of Service — openwrt CWE-191 6.5 Medium 2026-07-07
CVE-2026-58652 luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter — luci-app-travelmate CWE-78 7.5 High 2026-07-02
CVE-2026-58000 luci-proto-openvpn - Command Injection via cl_meta Parameter in generateKey — luci-proto-openvpn CWE-78 8.8 High 2026-06-29
CVE-2026-57999 luci-app-tailscale-community - Command Injection via tailscale.do_login RPC — luci-app-tailscale-community CWE-78 8.8 High 2026-06-29
CVE-2026-32721 LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal — luci CWE-79 8.6 High 2026-03-19
CVE-2026-30874 OpenWrt procd PATH Environment Variable Filter Bypass via Incorrect String Comparison Leads to Privilege Escalation — openwrt CWE-187 8.8 - 2026-03-19
CVE-2026-30873 OpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokens — openwrt CWE-401 7.5 - 2026-03-19
CVE-2026-30872 OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookup — openwrt CWE-121 10.0 - 2026-03-19
CVE-2026-30871 OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Query — openwrt CWE-121 10.0 - 2026-03-19
CVE-2025-62526 OpenWrt ubusd vulnerable to heap buffer overflow — openwrt CWE-122 7.9 High 2025-10-22
CVE-2025-62525 OpenWrt vulnerable to local privilage escalation — openwrt CWE-20 7.9 High 2025-10-22
CVE-2024-54143 openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection — asu CWE-328 8.8 - 2024-12-06
CVE-2019-5102 OpenWrt 信任管理问题漏洞 — OpenWRT CWE-295 4.0 Medium 2019-11-18
CVE-2019-5101 OpenWrt 信任管理问题漏洞 — OpenWRT CWE-295 4.0 Medium 2019-11-18

This page lists every published CVE security advisory associated with OpenWRT. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.