<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – OpenWrt</title>
  <link>https://cvedaily.com/pages/tags/openwrt.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/openwrt.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – OpenWrt</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:43 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-46368 – luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-46368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-46368</guid>
    <pubDate>Tue, 26 May 2026 15:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-46368</strong></p>
  <p>luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — contains a command injection vulnerability in the setInitAction function. An authenticated user holding the luci.https-dns-proxy ACL permission can inject shell metacharacters through the 'name' param…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-46368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-43173 – In the Linux kernel, the following vulnerability has been resolved:

net: ethern...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-43173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-43173</guid>
    <pubDate>Wed, 06 May 2026 12:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-43173</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  net: ethernet: xscale: Check for PTP support properly  In ixp4xx_get_ts_info() ixp46x_ptp_find() is called unconditionally despite this feature only existing on ixp46x, leading to the following splat from tcpdump:  root@OpenWrt:~# tcpdump -vv -X -i eth0 (...) Unable to handle kernel NULL pointer dereference at virtual address…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32721 – LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32721</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32721</guid>
    <pubDate>Thu, 19 Mar 2026 23:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32721</strong></p>
  <p>LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template literal to dom.append(), which processes them through innerHTML, allowing an at…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32721">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-30874 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30874</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30874</guid>
    <pubDate>Thu, 19 Mar 2026 23:16:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-30874</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject an arbitrary PATH variable, potentially leading to privilege escalation. The function is intended to filter out sensitive environment variables like PATH when executing hotplug scri…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30874">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-30873 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30873</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30873</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-30873</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, the jp_get_token function, which performs lexical analysis by breaking input expressions into tokens, contains a memory leak vulnerability when extracting string literals, field labels, and regular expressions using dynamic memory allocation. These extracted results are stored in…</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30873">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30872 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30872</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30872</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30872</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast DNS on UDP port 5353. During processing, the domain name from name_buffer is copi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30872">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-30871 – OpenWrt Project is a Linux operating system targeting embedded devices. In versi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-30871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-30871</guid>
    <pubDate>Thu, 19 Mar 2026 22:16:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-30871</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is  triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dn_expand into an 8096-byte global buffer…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-121</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-30871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62526 – OpenWrt Project is a Linux operating system targeting embedded devices. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62526</guid>
    <pubDate>Wed, 22 Oct 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62526</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, ubusd contains a heap buffer overflow in the event registration parsing code. This allows an attacker to modify the head and potentially execute arbitrary code in the context of the ubus daemon. The affected code is executed before running the ACL checks, all ubus clients are able to send such messag…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-122</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62526">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-62525 – OpenWrt Project is a Linux operating system targeting embedded devices. Prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-62525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-62525</guid>
    <pubDate>Wed, 22 Oct 2025 15:16:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-62525</strong></p>
  <p>OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the datapath of the DSL line. This only effects the lantiq target supporting xrx200, danube and amazon SoCs from Lantiq/Intel/MaxLinear with the DSL in PTM mode. The DSL driver for t…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-62525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-57389 – A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packag...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-57389</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-57389</guid>
    <pubDate>Wed, 01 Oct 2025 21:16:42 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-57389</strong></p>
  <p>A reflected cross-site scripting (XSS) vulnerability in the /admin/system/packages endpoint of Luci OpenWRT v18.06.2 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. This vulnerability was fixed in OpenWRT v19.07.0.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-57389">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-56706 – Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE)...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-56706</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-56706</guid>
    <pubDate>Tue, 16 Sep 2025 12:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-56706</strong></p>
  <p>Edimax BR-6473AX v1.0.28 was discovered to contain a remote code execution (RCE) vulnerability via the Object parameter in the openwrt_getConfig function.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-56706">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-49073 – In the Linux kernel, the following vulnerability has been resolved:

ata: sata_d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-49073</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-49073</guid>
    <pubDate>Wed, 26 Feb 2025 07:00:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-49073</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  ata: sata_dwc_460ex: Fix crash due to OOB write  the driver uses libata's "tag" values from in various arrays. Since the mentioned patch bumped the ATA_TAG_INTERNAL to 32, the value of the SATA_DWC_QCMD_MAX needs to account for that.  Otherwise ATA_TAG_INTERNAL usage cause similar crashes like this as reported by Tice Rex on the…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-49073">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-53223 – In the Linux kernel, the following vulnerability has been resolved:

clk: ralink...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-53223</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-53223</guid>
    <pubDate>Fri, 27 Dec 2024 14:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-53223</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  clk: ralink: mtmips: fix clocks probe order in oldest ralink SoCs  Base clocks are the first in being probed and are real dependencies of the rest of fixed, factor and peripheral clocks. For old ralink SoCs RT2880, RT305x and RT3883 'xtal' must be defined first since in any other case, when fixed clocks are probed they are delay…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-53223">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-54143 – openwrt/asu is an image on demand server for OpenWrt based distributions. The re...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54143</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54143</guid>
    <pubDate>Fri, 06 Dec 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-54143</strong></p>
  <p>openwrt/asu is an image on demand server for OpenWrt based distributions. The request hashing mechanism truncates SHA-256 hashes to only 12 characters. This significantly reduces entropy, making it feasible for an attacker to generate collisions. By exploiting this, a previously built malicious image can be served in place of a legitimate one, allowing the attacker to "poison" the artifact cache…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-328</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54143">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-51240 – An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege es...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-51240</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-51240</guid>
    <pubDate>Tue, 05 Nov 2024 19:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-51240</strong></p>
  <p>An issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API, which is exposed by the luci-mod-rpc package</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-51240">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30312 – An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30312</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30312</guid>
    <pubDate>Tue, 28 May 2024 22:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30312</strong></p>
  <p>An issue discovered in OpenWrt 18.06, 19.07, 21.02, 22.03, and beyond allows off-path attackers to hijack TCP sessions, which could lead to a denial of service, impersonating the client to the server (e.g., for access to files over FTP), and impersonating the server to the client (e.g., to deliver false information from a finance website). This occurs because nf_conntrack_tcp_no_window_check is t…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30312">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-41102 – An issue was discovered in the captive portal in OpenNDS before version 10.1.3. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41102</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-41102</strong></p>
  <p>An issue was discovered in the captive portal in OpenNDS before version 10.1.3. It has multiple memory leaks due to not freeing up allocated memory. This may lead to a Denial-of-Service condition due to the consumption of all available memory. Affected OpenNDS before version 10.1.3 fixed in OpenWrt master and OpenWrt 23.05 on 23. November by updating OpenNDS to version 10.2.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-401</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41101 – An issue was discovered in the captive portal in OpenNDS before version 10.1.3. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41101</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41101</strong></p>
  <p>An issue was discovered in the captive portal in OpenNDS before version 10.1.3. get_query in http_microhttpd.c does not validate the length of the query string of GET requests. This leads to a stack-based buffer overflow in versions 9.x and earlier, and to a heap-based buffer overflow in versions 10.x and later. Attackers may exploit the issue to crash OpenNDS (Denial-of-Service condition) or to…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38324 – An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the sp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38324</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38324</strong></p>
  <p>An issue was discovered in OpenNDS before 10.1.2. It allows users to skip the splash page sequence (and directly authenticate) when it is using the default FAS key and OpenNDS is configured as FAS. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38322 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38322</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38322</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a do_binauth NULL pointer dereference that be triggered with a crafted GET HTTP request with a missing User-Agent HTTP header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the BinAuth opt…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38320 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38320</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38320</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38320</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a show_preauthpage NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing User-Agent header. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). This problem was fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38320">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38316 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38316</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38316</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38316</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-116</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38316">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38315 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38315</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38315</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a try_to_authenticate NULL pointer dereference that can be triggered with a crafted GET HTTP with a missing client token query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.0…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-38314 – An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38314</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38314</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-38314</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before version 10.1.2. It has a NULL pointer dereference in preauthenticated() that can be triggered with a crafted GET HTTP request with a missing redirect query string parameter. Triggering this issue results in crashing OpenNDS (a Denial-of-Service condition). Affected OpenNDS Captive Portal before version 10.1.2 fixed infixed in OpenWrt master…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38314">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-38313 – An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_bin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38313</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38313</guid>
    <pubDate>Fri, 17 Nov 2023 06:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-38313</strong></p>
  <p>An issue was discovered in OpenNDS Captive Portal before 10.1.2. it has a do_binauth NULL pointer dereference that can be triggered with a crafted GET HTTP request with a missing client redirect query string parameter. Triggering this issue results in crashing openNDS (a Denial-of-Service condition). The issue occurs when the client is about to be authenticated, and can be triggered only when the…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38313">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24182 – LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a s...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24182</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24182</guid>
    <pubDate>Tue, 11 Apr 2023 01:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24182</strong></p>
  <p>LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /system/sshkeys.js.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24182">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-24181 – LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-24181</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-24181</guid>
    <pubDate>Mon, 10 Apr 2023 14:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-24181</strong></p>
  <p>LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /openvpn/pageswitch.htm.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-24181">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-41435 – OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-41435</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-41435</guid>
    <pubDate>Thu, 03 Nov 2022 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-41435</strong></p>
  <p>OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in the component /system/sshkeys.js. This vulnerability allows attackers to execute arbitrary web scripts or HTML via crafted public key comments.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-41435">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-38333 – Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-38333</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-38333</guid>
    <pubDate>Mon, 19 Sep 2022 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-38333</strong></p>
  <p>Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-38333">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-45906 – OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45906</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45906</guid>
    <pubDate>Mon, 27 Dec 2021 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-45906</strong></p>
  <p>OpenWrt 21.02.1 allows XSS via the NAT Rules Name screen.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45906">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-45905 – OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45905</guid>
    <pubDate>Mon, 27 Dec 2021 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-45905</strong></p>
  <p>OpenWrt 21.02.1 allows XSS via the Traffic Rules Name screen.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-45904 – OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-45904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-45904</guid>
    <pubDate>Mon, 27 Dec 2021 23:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-45904</strong></p>
  <p>OpenWrt 21.02.1 allows XSS via the Port Forwards Add Name screen.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-45904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32019 – There is missing input validation of host names displayed in OpenWrt before 19.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32019</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32019</guid>
    <pubDate>Mon, 02 Aug 2021 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32019</strong></p>
  <p>There is missing input validation of host names displayed in OpenWrt before 19.07.8. The Connection Status page of the luci web-interface allows XSS, which can be used to gain full control over the affected system via ICMP.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32019">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-33425 – A stored cross-site scripting (XSS) vulnerability was discovered in the Web Inte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-33425</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-33425</guid>
    <pubDate>Tue, 25 May 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-33425</strong></p>
  <p>A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-33425">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27821 – The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27821</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27821</guid>
    <pubDate>Tue, 25 May 2021 14:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27821</strong></p>
  <p>The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability which can lead to attackers carrying out arbitrary code execution.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27821">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-28961 – applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-28961</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-28961</guid>
    <pubDate>Sun, 21 Mar 2021 06:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-28961</strong></p>
  <p>applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to inject arbitrary commands via POST requests.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-28961">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22161 – In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22161</guid>
    <pubDate>Sun, 07 Feb 2021 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22161</strong></p>
  <p>In OpenWrt 19.07.x before 19.07.7, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global uniqu…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-835</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13859 – An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A fo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13859</guid>
    <pubDate>Mon, 01 Feb 2021 02:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13859</strong></p>
  <p>An issue was discovered on Mofi Network MOFI4500-4GXeLTE 4.0.8-std devices. A format error in /etc/shadow, coupled with a logic bug in the LuCI - OpenWrt Configuration Interface framework, allows the undocumented system account mofidev to login to the cgi-bin/luci/quick/wizard management interface without a password by abusing a forgotten-password feature.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-25015 – LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25015</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25015</guid>
    <pubDate>Tue, 26 Jan 2021 18:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-25015</strong></p>
  <p>LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25015">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-28951 – libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use aft...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-28951</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-28951</guid>
    <pubDate>Thu, 19 Nov 2020 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-28951</strong></p>
  <p>libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-416</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-28951">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11968 – In the web-panel in IQrouter through 3.3.1, remote attackers can read system log...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11968</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11968</strong></p>
  <p>In the web-panel in IQrouter through 3.3.1, remote attackers can read system logs because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for any uncon…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11967 – In IQrouter through 3.3.1, remote attackers can control the device (restart netw...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11967</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11967</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11967</strong></p>
  <p>In IQrouter through 3.3.1, remote attackers can control the device (restart network, reboot, upgrade, reset) because of Incorrect Access Control. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerabi…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11967">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11966 – In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11966</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11966</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11966</strong></p>
  <p>In IQrouter through 3.3.1, the Lua function reset_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-521</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11966">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11965 – In IQrouter through 3.3.1, there is a root user without a password, which allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11965</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11965</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11965</strong></p>
  <p>In IQrouter through 3.3.1, there is a root user without a password, which allows attackers to gain full remote access via SSH. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerability is “true for a…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11965">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11964 – In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11964</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11964</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11964</strong></p>
  <p>In IQrouter through 3.3.1, the Lua function diag_set_password in the web-panel allows remote attackers to change the root password arbitrarily. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. This vulnerabili…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11964">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-11963 – IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11963</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11963</guid>
    <pubDate>Tue, 21 Apr 2020 13:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-11963</strong></p>
  <p>IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new network that, after initiating the forced initial configuration (which has a required step for setting a secure password on the system), makes this CVE invalid. Th…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11963">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-10871 – In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-10871</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-10871</guid>
    <pubDate>Mon, 23 Mar 2020 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-10871</strong></p>
  <p>In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and services. NOTE: the vendor disputes the significance of this report because, for instances reachable by an unauthenticated actor, the same information is available in other (more complex) ways, and there is no plan to restrict the information further</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-10871">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7982 – An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7982</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7982</guid>
    <pubDate>Mon, 16 Mar 2020 22:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7982</strong></p>
  <p>An issue was discovered in OpenWrt 18.06.0 to 18.06.6 and 19.07.0, and LEDE 17.01.0 to 17.01.7. A bug in the fork of the opkg package manager before 2020-01-25 prevents correct parsing of embedded checksums in the signed repository index, allowing a man-in-the-middle attacker to inject arbitrary package payloads (which are installed without verification).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-345</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7982">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7248 – libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary da...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7248</guid>
    <pubDate>Mon, 16 Mar 2020 21:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7248</strong></p>
  <p>libubox in OpenWrt before 18.06.7 and 19.x before 19.07.1 has a tagged binary data JSON serialization vulnerability that may cause a stack based buffer overflow.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-787</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-19945 – uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer si...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19945</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19945</guid>
    <pubDate>Mon, 16 Mar 2020 18:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-19945</strong></p>
  <p>uhttpd in OpenWrt through 18.06.5 and 19.x through 19.07.0-rc2 has an integer signedness error. This leads to out-of-bounds access to a heap buffer and a subsequent crash. It can be triggered with an HTTP POST request to a CGI script, specifying both "Transfer-Encoding: chunked" and a large negative Content-Length value.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19945">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18993 – OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18993</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18993</guid>
    <pubDate>Tue, 03 Dec 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18993</strong></p>
  <p>OpenWrt 18.06.4 allows XSS via the "New port forward" Name field to the cgi-bin/luci/admin/network/firewall/forwards URI (this can occur, for example, on a TP-Link Archer C7 device).</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18993">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-18992 – OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-18992</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-18992</guid>
    <pubDate>Tue, 03 Dec 2019 20:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-18992</strong></p>
  <p>OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-18992">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5102 – An exploitable information leak vulnerability exists in the ustream-ssl library ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5102</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5102</guid>
    <pubDate>Mon, 18 Nov 2019 18:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5102</strong></p>
  <p>An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5102">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-5101 – An exploitable information leak vulnerability exists in the ustream-ssl library ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-5101</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-5101</guid>
    <pubDate>Mon, 18 Nov 2019 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-5101</strong></p>
  <p>An exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting to a remote server, the server's SSL certificate is checked but no action is taken when the certificate is invalid. An attacker could exploit this behavior by performing a man-in-the-middle attack, providing any certificate, leading to the theft of all the data…</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-5101">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-17367 – OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.netwo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-17367</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-17367</guid>
    <pubDate>Fri, 18 Oct 2019 17:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-17367</strong></p>
  <p>OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firewall/forwards, firewall/rules, network/wan, network/wan6, or network/lan under /cgi-bin/luci/admin/network/.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-17367">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-15513 – An issue was discovered in OpenWrt libuci (aka Library for the Unified Configura...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15513</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15513</guid>
    <pubDate>Fri, 23 Aug 2019 07:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-15513</strong></p>
  <p>An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-667</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15513">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-9385 – An issue was discovered on Vera Veralite 1.7.481 devices. The device has an addi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-9385</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-9385</guid>
    <pubDate>Mon, 17 Jun 2019 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-9385</strong></p>
  <p>An issue was discovered on Vera Veralite 1.7.481 devices. The device has an additional OpenWRT interface in addition to the standard web interface which allows the highest privileges a user can obtain on the device. This web interface uses root as the username and the password in the /etc/cmh/cmh.conf file which can be extracted by an attacker using a directory traversal attack, and then log in t…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-255</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-9385">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-12272 – In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_stat...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-12272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-12272</guid>
    <pubDate>Thu, 23 May 2019 15:30:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-12272</strong></p>
  <p>In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-78</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-12272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-19630 – cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-19630</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-19630</guid>
    <pubDate>Wed, 28 Nov 2018 10:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-19630</strong></p>
  <p>cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-19630">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11116 – OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/ac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11116</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11116</guid>
    <pubDate>Tue, 19 Jun 2018 21:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11116</strong></p>
  <p>OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the file, log, and service namespaces, potentially leading to remote Information Disclosure or Code Execution. NOTE: The dev…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11116">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-17867 – Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-17867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-17867</guid>
    <pubDate>Thu, 04 Jan 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-17867</strong></p>
  <p>Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-17867">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
