Luci
Openwrt · 19 CVEs
luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root
Sep 21, 2026
luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow
Aug 22, 2026
OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass
Aug 13, 2026
luci-app-openvpn Path Traversal RCE via instance_name2
Aug 13, 2026
OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write
Aug 13, 2026
OpenWrt luci-app-dockerman Read ACL Remote Code Execution
Aug 3, 2026
OpenWrt luci-app-bmx7 Path Traversal via bmx7-info
Aug 3, 2026
luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name
Aug 2, 2026
luci-app-https-dns-proxy Stored XSS via resolver_url
Aug 1, 2026
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
Jul 12, 2026
luci-app-upnp Stored XSS via UPnP Port Mapping Description
Jul 12, 2026
OpenWrt luci-app-samba4 read ACL remote code execution via smbd
Jul 12, 2026
LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal
Mar 19, 2026
An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root…
Nov 5, 2024
LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vul…
Apr 10, 2023
OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerabili…
Nov 3, 2022
The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerabi…
May 25, 2021
In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NO…
Mar 23, 2020
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_s…
May 23, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-55897 | luci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as root | HIGH | 0.65% | Sep 21, 2026 |
| CVE-2026-62381 | luci-lib-px5g 2040-bit Certificate Signing Heap Buffer Overflow | MEDIUM | 0.11% | Aug 22, 2026 |
| CVE-2026-72842 | OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypass | CRITICAL | 0.62% | Aug 13, 2026 |
| CVE-2026-72841 | luci-app-openvpn Path Traversal RCE via instance_name2 | CRITICAL | 0.62% | Aug 13, 2026 |
| CVE-2026-72840 | OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Write | HIGH | 0.44% | Aug 13, 2026 |
| CVE-2026-69096 | OpenWrt luci-app-dockerman Read ACL Remote Code Execution | HIGH | 3.27% | Aug 3, 2026 |
| CVE-2026-69095 | OpenWrt luci-app-bmx7 Path Traversal via bmx7-info | HIGH | 0.93% | Aug 3, 2026 |
| CVE-2026-68583 | luci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.name | MEDIUM | 0.24% | Aug 2, 2026 |
| CVE-2026-67352 | luci-app-https-dns-proxy Stored XSS via resolver_url | MEDIUM | 0.41% | Aug 1, 2026 |
| CVE-2026-61876 | LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting | CRITICAL | 1.28% | Jul 12, 2026 |
| CVE-2026-61875 | luci-app-upnp Stored XSS via UPnP Port Mapping Description | HIGH | 0.36% | Jul 12, 2026 |
| CVE-2026-59260 | OpenWrt luci-app-samba4 read ACL remote code execution via smbd | HIGH | 0.88% | Jul 12, 2026 |
| CVE-2026-32721 | LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal | HIGH | 0.29% | Mar 19, 2026 |
| CVE-2024-51240 | An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed b… | HIGH | 0.26% | Nov 5, 2024 |
| CVE-2023-24181 | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pa… | MEDIUM | 0.60% | Apr 10, 2023 |
| CVE-2022-41435 | OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js.… | MEDIUM | 0.51% | Nov 3, 2022 |
| CVE-2021-27821 | The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability. | MEDIUM | 0.59% | May 25, 2021 |
| CVE-2020-10871 | In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance… | MEDIUM | 1.68% | Mar 23, 2020 |
| CVE-2019-12272 | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affecte… | CRITICAL | 7.37% | May 23, 2019 |
Showing 1 to 19 of 19 CVEs