Vulnerabilidades em OpenWRT
30 resultadosAnálise Vexday
OpenWRT apresenta um panorama de risco reduzido com apenas 2 vulnerabilidades cadastradas na base, nenhuma sob ataque ativo ou classificada como crítica. A fraqueza dominante é relacionada a validação inadequada de certificados (CWE-295), característica típica de problemas de implementação TLS/SSL que, embora relevantes, não se manifestaram em exploração conhecida. Não há atividade de descoberta recente, indicando estabilidade relativa no perfil de segurança do projeto.
CVE-2026-58000HIGHluci-proto-openvpn - Command Injection via cl_meta Parameter in generateKeyEPSS 2.7%CVE-2026-57999HIGHluci-app-tailscale-community - Command Injection via tailscale.do_login RPCEPSS 2.3%CVE-2026-30872CRITICALOpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupEPSS 2.2%CVE-2024-54143CRITICALopenwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionEPSS 1.8%CVE-2026-69096HIGHOpenWrt luci-app-dockerman Read ACL Remote Code ExecutionEPSS 1.7%CVE-2026-61876CRITICALLuCI DHCPv6 Lease Hostname Stored Cross-Site ScriptingEPSS 1.3%CVE-2026-30871CRITICALOpenWrt Project has Stack-based Buffer Overflow in DNS PTR QueryEPSS 1.2%CVE-2026-58652HIGHluci-app-travelmate - Arbitrary Command Execution via UCI Script ParameterEPSS 0.8%CVE-2026-62184HIGHluci-app-banip Log Monitor IP Extraction BypassEPSS 0.8%CVE-2026-69095HIGHOpenWrt luci-app-bmx7 Path Traversal via bmx7-infoEPSS 0.8%CVE-2019-5102MEDIUMAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting toEPSS 0.8%CVE-2019-5101MEDIUMAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting toEPSS 0.8%CVE-2026-55490MEDIUMOpenWrt: EAD Integer Underflow → Pre-Auth Denial of ServiceEPSS 0.7%CVE-2026-59260HIGHOpenWrt luci-app-samba4 read ACL remote code execution via smbdEPSS 0.7%CVE-2026-62948CRITICALOpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UIEPSS 0.6%CVE-2026-61875HIGHluci-app-upnp Stored XSS via UPnP Port Mapping DescriptionEPSS 0.6%CVE-2026-72841CRITICALluci-app-openvpn Path Traversal RCE via instance_name2EPSS 0.5%CVE-2026-62947MEDIUMOpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-downloadEPSS 0.5%CVE-2026-30873LOWOpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokensEPSS 0.5%CVE-2026-72842CRITICALOpenWrt luci-app-lxc ACL Inconsistency Authentication BypassEPSS 0.4%