← Back

Openwrt

openwrt

143 CVEs • 4 products

Products (4)

Click to collapse
Toggle
Openwrt
openwrt
Luci
luci
Lede
lede
Libuci
libuci

CVEs (143)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Openwrt
1Luci
Jun 17, 2026
May 23, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
1Openwrt
2Lede
Openwrt
Nov 21, 2024
Nov 28, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
1Openwrt
1Openwrt
Nov 21, 2024
Jun 19, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed t...Show more
OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the file, log, and service namespaces, potentially leading to remote Information Disclosure or Code Execution. NOTE: The developer disputes this as a vulnerability, indicating that rpcd functions appropriatelyShow less