Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-62948 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh… Openwrt 25.12.5+ Fix from $2,3002026-07-15 MEDIUM 6.5 CVE-2026-55490 OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daem… Openwrt 25.12.5+ Fix from $1,6002026-07-07 HIGH 7.8 CVE-2026-30874 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function al… Openwrt 24.10.6+ Fix from $1,9502026-03-19 CRITICAL 9.8 CVE-2026-30871 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based B… Openwrt 24.10.6 / 25.12.1+ Fix from $2,3002026-03-19 CRITICAL 9.8 CVE-2026-30872 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based B… Openwrt 24.10.6 / 25.12.1+ Fix from $2,3002026-03-19 HIGH 8.8 CVE-2025-62525 OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel m… Openwrt 24.10.4+ Fix from $1,9502025-10-22 HIGH 7.8 CVE-2025-62526 OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event … Openwrt 24.10.4+ Fix from $1,9502025-10-22 CRITICAL 9.8 CVE-2025-20674 In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of priv… Openwrt after 7.6.7.2 Fix from $2,3002025-06-02 HIGH 7.2 CVE-2023-20820 In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System executi… Openwrt Mitigation only Fix from $1,9502023-09-04 MEDIUM 5.4 CVE-2023-24182 LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /sys… Openwrt Patch available Fix from $1,6002023-04-11 MEDIUM 5.4 CVE-2023-24181 LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /… Luci Patch available Fix from $1,6002023-04-10 MEDIUM 5.4 CVE-2022-41435 OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/ss… Luci Patch available Fix from $1,6002022-11-03 HIGH 7.5 CVE-2022-38333 Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows … Openwrt 21.02.3+ Fix from $1,9502022-09-19 MEDIUM 5.4 CVE-2021-45904 OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen. Openwrt No fix yet Fix from $1,6002021-12-27 MEDIUM 5.4 CVE-2021-45905 OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen. Openwrt No fix yet Fix from $1,6002021-12-27 MEDIUM 5.4 CVE-2021-45906 OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen. Openwrt No fix yet Fix from $1,6002021-12-27 MEDIUM 6.1 CVE-2021-32019 There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the luci web-interface allows XSS,… Openwrt 19.07.8+ Fix from $1,6002021-08-02 MEDIUM 6.1 CVE-2021-27821 The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability. Luci after 19.07.0 Fix from $1,6002021-05-25 MEDIUM 5.4 CVE-2021-33425 A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject… Openwrt Patch available Fix from $1,6002021-05-25 HIGH 8.8 CVE-2021-28961 applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitra… Openwrt Patch available Fix from $1,9502021-03-21 MEDIUM 6.5 CVE-2021-22161 In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device an… Openwrt after 19.07.6 Fix from $1,6002021-02-07 MEDIUM 5.4 CVE-2019-25015 LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID. Openwrt after 18.06.4 Fix from $1,6002021-01-26 CRITICAL 9.8 CVE-2020-28951 libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_pa… Openwrt 18.06.9 / 19.07.5+ Fix from $2,3002020-11-19 MEDIUM 5.3 CVE-2020-10871 In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the si… Luci Patch available Fix from $1,6002020-03-23 HIGH 8.1 CVE-2020-7982 An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before … Lede 18.06.7+ Fix from $1,9502020-03-16 HIGH 7.5 CVE-2020-7248 libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that may cause a stack based buff… Openwrt 18.06.7+ Fix from $1,9502020-03-16 HIGH 7.5 CVE-2019-19945 uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer a… Openwrt after 18.06.5 Fix from $1,9502020-03-16 MEDIUM 5.4 CVE-2019-18992 OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" … Openwrt Patch available Fix from $1,6002019-12-03 MEDIUM 5.4 CVE-2019-18993 OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example… Openwrt Patch available Fix from $1,6002019-12-03 MEDIUM 5.9 CVE-2019-5102 An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote… Openwrt No fix yet Fix from $1,6002019-11-18