<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenWrt (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/openwrt.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openwrt-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenWrt (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46368 – luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46368</guid>
    <pubDate>Tue, 26 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46368</strong></p>
  <p>luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' param…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32721 – LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32721</guid>
    <pubDate>Thu, 19 Mar 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32721</strong></p>
  <p>LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template literal to dom.append(), which processes them through innerHTML, allowing an at…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30874 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30874</guid>
    <pubDate>Thu, 19 Mar 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30874</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject an arbitrary PATH variable, potentially leading to privilege escalation. The function is intended to filter out sensitive environment variables like PATH when executing hotplug scri…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30872 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30872</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30872</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast DNS on UDP port 5353. During processing, the domain name from name_buffer is copi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30871 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30871</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30871</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is  triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dn_expand into an 8096-byte global buffer…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62526 – OpenWrt Project is a Linux operating system targeting embedded devices. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62526</guid>
    <pubDate>Wed, 22 Oct 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62526</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messag…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62525 – OpenWrt Project is a Linux operating system targeting embedded devices. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62525</guid>
    <pubDate>Wed, 22 Oct 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62525</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the datapath of the DSL line. This only effects the lantiq target supporting xrx200, danube and amazon SoCs from Lantiq/Intel/MaxLinear with the DSL in PTM mode. The DSL driver for t…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56706 – Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56706</guid>
    <pubDate>Tue, 16 Sep 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56706</strong></p>
  <p>Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49073 – In the Linux kernel, the following vulnerability has been resolved:

ata: sata_d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49073</guid>
    <pubDate>Wed, 26 Feb 2025 07:00:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49073</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ata: sata_dwc_460ex: Fix crash due to OOB write  the driver uses libata's "tag" values from in various arrays. Since the mentioned patch bumped the ATA_TAG_INTERNAL to 32, the value of the SATA_DWC_QCMD_MAX needs to account for that.  Otherwise ATA_TAG_INTERNAL usage cause similar crashes like this as reported by Tice Rex on the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-54143 – openwrt/asu is an image on demand server for OpenWrt based distributions. The re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54143</guid>
    <pubDate>Fri, 06 Dec 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-54143</strong></p>
  <p>openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51240 – An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege es...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51240</guid>
    <pubDate>Tue, 05 Nov 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51240</strong></p>
  <p>An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30312 – An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30312</guid>
    <pubDate>Tue, 28 May 2024 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30312</strong></p>
  <p>An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of service, impersonating the client to the server (e.g., for access to files over FTP), and impersonating the server to the client (e.g., to deliver false information from a finance website). This occurs because nf_conntrack_tcp_no_window_check is t…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41102 – An issue was discovered in the captive portal in OpenNDS before version 10.1.3. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41102</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41102</strong></p>
  <p>An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41101 – An issue was discovered in the captive portal in OpenNDS before version 10.1.3. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41101</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41101</strong></p>
  <p>An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer overflow in versions 10.x and later. Attackers may exploit the issue to crash OpenNDS (Denial-of-Service condition) or to…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38322 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38322</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38322</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth opt…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38320 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38320</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38320</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). This problem was fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38316 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38316</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38316</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38315 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38315</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38315</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38313 – An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_bin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38313</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38313</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38333 – Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38333</guid>
    <pubDate>Mon, 19 Sep 2022 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38333</strong></p>
  <p>Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28961 – applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28961</guid>
    <pubDate>Sun, 21 Mar 2021 06:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28961</strong></p>
  <p>applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13859 – An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13859</guid>
    <pubDate>Mon, 01 Feb 2021 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13859</strong></p>
  <p>An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-28951 – libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use aft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28951</guid>
    <pubDate>Thu, 19 Nov 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-28951</strong></p>
  <p>libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11968 – In the web-panel in IQrouter through 3.3.1, remote attackers can read system log...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11968</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11968</strong></p>
  <p>In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any uncon…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11967 – In IQrouter through 3.3.1, remote attackers can control the device (restart netw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11967</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11967</strong></p>
  <p>In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerabi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11966 – In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11966</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11966</strong></p>
  <p>In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11965 – In IQrouter through 3.3.1, there is a root user without a password, which allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11965</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11965</strong></p>
  <p>In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11964 – In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11964</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11964</strong></p>
  <p>In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerabili…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11963 – IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11963</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11963</strong></p>
  <p>IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. Th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7982 – An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7982</guid>
    <pubDate>Mon, 16 Mar 2020 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7982</strong></p>
  <p>An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7248 – libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7248</guid>
    <pubDate>Mon, 16 Mar 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7248</strong></p>
  <p>libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that may cause a stack based buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19945 – uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19945</guid>
    <pubDate>Mon, 16 Mar 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19945</strong></p>
  <p>uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17367 – OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17367</guid>
    <pubDate>Fri, 18 Oct 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17367</strong></p>
  <p>OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15513 – An issue was discovered in OpenWrt libuci (aka Library for the Unified Configura...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15513</guid>
    <pubDate>Fri, 23 Aug 2019 07:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15513</strong></p>
  <p>An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-9385 – An issue was discovered on Vera Veralite 1.7.481 devices. The device has an addi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9385</guid>
    <pubDate>Mon, 17 Jun 2019 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-9385</strong></p>
  <p>An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface which allows the highest privileges a user can obtain on the device. This web interface uses root as the username and the password in the /etc/cmh/cmh.conf file which can be extracted by an attacker using a directory traversal attack, and then log in t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12272 – In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_stat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12272</guid>
    <pubDate>Thu, 23 May 2019 15:30:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12272</strong></p>
  <p>In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11116 – OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11116</guid>
    <pubDate>Tue, 19 Jun 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11116</strong></p>
  <p>OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the file, log, and service namespaces, potentially leading to remote Information Disclosure or Code Execution. NOTE: The dev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17867 – Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17867</guid>
    <pubDate>Thu, 04 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17867</strong></p>
  <p>Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17867">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
