Vulnerabilidades em openwrt

30 resultados
Análise Vexday

OpenWrt apresenta 18 vulnerabilidades catalogadas, com concentração recente de 10 divulgações nos últimos 90 dias, indicando pressão contínua de correções. A fraqueza dominante é XSS (CWE-79), típica de interfaces web, com 5 vulnerabilidades críticas que demandam atenção imediata. Não há evidências de exploração ativa em wild (KEV), mas o volume e recência sugerem risco substancial para ambientes que não mantêm patches atualizados.

CVE-2026-58000HIGHluci-proto-openvpn - Command Injection via cl_meta Parameter in generateKeyEPSS 2.7%CVE-2026-57999HIGHluci-app-tailscale-community - Command Injection via tailscale.do_login RPCEPSS 2.3%CVE-2026-30872CRITICALOpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupEPSS 2.2%CVE-2024-54143CRITICALopenwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionEPSS 1.8%CVE-2026-69096HIGHOpenWrt luci-app-dockerman Read ACL Remote Code ExecutionEPSS 1.7%CVE-2026-61876CRITICALLuCI DHCPv6 Lease Hostname Stored Cross-Site ScriptingEPSS 1.3%CVE-2026-30871CRITICALOpenWrt Project has Stack-based Buffer Overflow in DNS PTR QueryEPSS 1.2%CVE-2026-58652HIGHluci-app-travelmate - Arbitrary Command Execution via UCI Script ParameterEPSS 0.8%CVE-2026-62184HIGHluci-app-banip Log Monitor IP Extraction BypassEPSS 0.8%CVE-2026-69095HIGHOpenWrt luci-app-bmx7 Path Traversal via bmx7-infoEPSS 0.8%CVE-2019-5102MEDIUMAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting toEPSS 0.8%CVE-2019-5101MEDIUMAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting toEPSS 0.8%CVE-2026-55490MEDIUMOpenWrt: EAD Integer Underflow → Pre-Auth Denial of ServiceEPSS 0.7%CVE-2026-59260HIGHOpenWrt luci-app-samba4 read ACL remote code execution via smbdEPSS 0.7%CVE-2026-62948CRITICALOpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UIEPSS 0.6%CVE-2026-61875HIGHluci-app-upnp Stored XSS via UPnP Port Mapping DescriptionEPSS 0.6%CVE-2026-72841CRITICALluci-app-openvpn Path Traversal RCE via instance_name2EPSS 0.5%CVE-2026-62947MEDIUMOpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-downloadEPSS 0.5%CVE-2026-30873LOWOpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokensEPSS 0.5%CVE-2026-55159HIGHluci-app-adblock-fast: Delegated `luci-app-adblock-fast` users can reach root command execution by injecting newline-separated cron entriesEPSS 0.5%