Vulnerabilidades em OpenWRT
30 resultadosAnálise Vexday
OpenWRT apresenta um panorama de risco reduzido com apenas 2 vulnerabilidades cadastradas na base, nenhuma sob ataque ativo ou classificada como crítica. A fraqueza dominante é relacionada a validação inadequada de certificados (CWE-295), característica típica de problemas de implementação TLS/SSL que, embora relevantes, não se manifestaram em exploração conhecida. Não há atividade de descoberta recente, indicando estabilidade relativa no perfil de segurança do projeto.
CVE-2026-55897HIGHluci-app-advanced-reboot read ACL exposes /bin/sh through file.exec, allowing delegated users to run commands as rootEPSS 0.5%CVE-2026-72842CRITICALOpenWrt luci-app-lxc ACL Inconsistency Authentication BypassEPSS 0.4%CVE-2026-72840HIGHOpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab WriteEPSS 0.4%CVE-2026-30874LOWOpenWrt procd PATH Environment Variable Filter Bypass via Incorrect String Comparison Leads to Privilege EscalationEPSS 0.3%CVE-2025-62526HIGHOpenWrt ubusd vulnerable to heap buffer overflowEPSS 0.3%CVE-2026-32721HIGHLuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modalEPSS 0.2%CVE-2026-67352MEDIUMluci-app-https-dns-proxy Stored XSS via resolver_urlEPSS 0.2%CVE-2025-62525HIGHOpenWrt vulnerable to local privilage escalationEPSS 0.2%CVE-2026-68583MEDIUMluci-app-adblock-fast before 1.2.4-4 Stored XSS via file_url.nameEPSS 0.2%CVE-2026-62381MEDIUMluci-lib-px5g 2040-bit Certificate Signing Heap Buffer OverflowEPSS 0.1%