Luci

Openwrt · 19 CVEs

CVE-2026-55897
HIGH

luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root

Sep 21, 2026

CVE-2026-62381
MEDIUM

luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow

Aug 22, 2026

CVE-2026-72842
CRITICAL

OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass

Aug 13, 2026

CVE-2026-72841
CRITICAL

luci-app-openvpn Path Traversal RCE via instance_name2

Aug 13, 2026

CVE-2026-72840
HIGH

OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write

Aug 13, 2026

CVE-2026-69096
HIGH

OpenWrt luci-app-dockerman Read ACL Remote Code Execution

Aug 3, 2026

CVE-2026-69095
HIGH

OpenWrt luci-app-bmx7 Path Traversal via bmx7-info

Aug 3, 2026

CVE-2026-68583
MEDIUM

luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name

Aug 2, 2026

CVE-2026-67352
MEDIUM

luci-app-https-dns-proxy Stored XSS via resolver_url

Aug 1, 2026

CVE-2026-61876
CRITICAL

LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting

Jul 12, 2026

CVE-2026-61875
HIGH

luci-app-upnp Stored XSS via UPnP Port Mapping Description

Jul 12, 2026

CVE-2026-59260
HIGH

OpenWrt luci-app-samba4 read ACL remote code execution via smbd

Jul 12, 2026

CVE-2026-32721
HIGH

LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal

Mar 19, 2026

CVE-2024-51240
HIGH

An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root…

Nov 5, 2024

CVE-2023-24181
MEDIUM

LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vul…

Apr 10, 2023

CVE-2022-41435
MEDIUM

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerabili…

Nov 3, 2022

CVE-2021-27821
MEDIUM

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerabi…

May 25, 2021

CVE-2020-10871
MEDIUM

In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NO…

Mar 23, 2020

CVE-2019-12272
CRITICAL

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_s…

May 23, 2019

Showing 1 to 19 of 19 CVEs