Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Openwrt CRITICAL 9.6
CVE-2026-62948

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh…

Fix: 25.12.5+
Fix from $2,300 2026-07-15
Openwrt MEDIUM 6.5
CVE-2026-55490

OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daem…

Fix: 25.12.5+
Fix from $1,600 2026-07-07
Openwrt HIGH 7.8
CVE-2026-30874

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function al…

Fix: 24.10.6+
Fix from $1,950 2026-03-19
Openwrt CRITICAL 9.8
CVE-2026-30871

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based B…

Fix: 24.10.6 / 25.12.1+
Fix from $2,300 2026-03-19
Openwrt CRITICAL 9.8
CVE-2026-30872

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based B…

Fix: 24.10.6 / 25.12.1+
Fix from $2,300 2026-03-19
Openwrt HIGH 8.8
CVE-2025-62525

OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel m…

Fix: 24.10.4+
Fix from $1,950 2025-10-22
Openwrt HIGH 7.8
CVE-2025-62526

OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event …

Fix: 24.10.4+
Fix from $1,950 2025-10-22
Openwrt CRITICAL 9.8
CVE-2025-20674

In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of priv…

Fix: after 7.6.7.2
Fix from $2,300 2025-06-02
Openwrt HIGH 7.2
CVE-2023-20820

In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System executi…

Mitigation only
Fix from $1,950 2023-09-04
Openwrt MEDIUM 5.4
CVE-2023-24182

LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /sys…

Patch available
Fix from $1,600 2023-04-11
Luci MEDIUM 5.4
CVE-2023-24181

LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /…

Patch available
Fix from $1,600 2023-04-10
Luci MEDIUM 5.4
CVE-2022-41435

OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/ss…

Patch available
Fix from $1,600 2022-11-03
Openwrt HIGH 7.5
CVE-2022-38333

Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows …

Fix: 21.02.3+
Fix from $1,950 2022-09-19
Openwrt MEDIUM 5.4
CVE-2021-45904

OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.

No fix yet
Fix from $1,600 2021-12-27
Openwrt MEDIUM 5.4
CVE-2021-45905

OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.

No fix yet
Fix from $1,600 2021-12-27
Openwrt MEDIUM 5.4
CVE-2021-45906

OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.

No fix yet
Fix from $1,600 2021-12-27
Openwrt MEDIUM 6.1
CVE-2021-32019

There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the luci web-interface allows XSS,…

Fix: 19.07.8+
Fix from $1,600 2021-08-02
Luci MEDIUM 6.1
CVE-2021-27821

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.

Fix: after 19.07.0
Fix from $1,600 2021-05-25
Openwrt MEDIUM 5.4
CVE-2021-33425

A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject…

Patch available
Fix from $1,600 2021-05-25
Openwrt HIGH 8.8
CVE-2021-28961

applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitra…

Patch available
Fix from $1,950 2021-03-21
Openwrt MEDIUM 6.5
CVE-2021-22161

In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device an…

Fix: after 19.07.6
Fix from $1,600 2021-02-07
Openwrt MEDIUM 5.4
CVE-2019-25015

LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.

Fix: after 18.06.4
Fix from $1,600 2021-01-26
Openwrt CRITICAL 9.8
CVE-2020-28951

libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_pa…

Fix: 18.06.9 / 19.07.5+
Fix from $2,300 2020-11-19
Luci MEDIUM 5.3
CVE-2020-10871

In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the si…

Patch available
Fix from $1,600 2020-03-23
Lede HIGH 8.1
CVE-2020-7982

An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before …

Fix: 18.06.7+
Fix from $1,950 2020-03-16
Openwrt HIGH 7.5
CVE-2020-7248

libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that may cause a stack based buff…

Fix: 18.06.7+
Fix from $1,950 2020-03-16
Openwrt HIGH 7.5
CVE-2019-19945

uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer a…

Fix: after 18.06.5
Fix from $1,950 2020-03-16
Openwrt MEDIUM 5.4
CVE-2019-18992

OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" …

Patch available
Fix from $1,600 2019-12-03
Openwrt MEDIUM 5.4
CVE-2019-18993

OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example…

Patch available
Fix from $1,600 2019-12-03
Openwrt MEDIUM 5.9
CVE-2019-5102

An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote…

No fix yet
Fix from $1,600 2019-11-18