Vulnerabilities
143 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-62948 +1 in the same advisory: …62947 | OpenWrt is a Linux operating system targeting embedded devices. OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI rpcd-mod-luci getDHCPLeases displays through htdocs/luci-static/resources/view/status/include/40_dhcp.js and htdocs/luci-static/resources/luci.js dom.append as live HTML in the Active DHCPv6 Leases admin page. This vulnerability is fixed in 25.12.5. NVD description · AI analysis pending | 9.6 group max | <1% | PoC |
| — | |
| CVE-2026-55490 | OpenWrt is a Linux operating system targeting embedded devices. OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows before a bounds check and is then passed to memcpy as a very large size. This issue is fixed v25.12.5. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2026-32721 | LuCI is the OpenWrt Configuration Interface. LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template literal to dom.append(), which processes them through innerHTML, allowing an attacker to craft a malicious SSID containing arbitrary HTML/JavaScript. Exploitation requires the user to actively open the wireless scan modal (e.g., to connect to a Wi-Fi access point or survey nearby channels), and only affects OpenWrt versions newer than 23.05/22.03 up to the patched releases (24.10.6 and 25.12.1). The issue has been fixed in version LuCI 26.072.65753~068150b. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2026-30872 | OpenWrt Project is a Linux operating system targeting embedded devices. OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast DNS on UDP port 5353. During processing, the domain name from name_buffer is copied via strcpy into a fixed 256-byte stack buffer, and then the reverse IPv6 request is extracted into a buffer of only 46 bytes (INET6_ADDRSTRLEN). Because the length of the data is never validated before this extraction, an attacker can supply input larger than 46 bytes, causing an out-of-bounds write. This allows a specially crafted DNS query to overflow the stack buffer in match_ipv6_addresses, potentially enabling remote code execution. This issue has been fixed in versions 24.10.6 and 25.12.1. NVD description · AI analysis pending | 9.5 group max | 2% |
| — | ||
| CVE-2026-20435 | In preloader, there is a possible read of device unique identifiers due to a logic error. In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10607099; Issue ID: MSV-6118. NVD description · AI analysis pending | 4.6 | <1% |
| — | ||
| CVE-2026-20430 | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00467553; Issue ID: MSV-5151. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2026-20419 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461663 / WCNCR00463309; Issue ID: MSV-4852. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2026-20408 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461651; Issue ID: MSV-4758. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2025-20765 | In aee daemon, there is a possible system crash due to a race condition. In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10190802; Issue ID: MSV-4833. NVD description · AI analysis pending | 4.7 | <1% |
| — | ||
| CVE-2025-20742 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00432680; Issue ID: MSV-3949. NVD description · AI analysis pending | 8.0 group max | <1% |
| — | ||
| CVE-2025-20747 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966. NVD description · AI analysis pending | 6.7 | <1% |
| — | ||
| CVE-2025-62525 +1 in the same advisory: …62526 | OpenWrt Project is a Linux operating system targeting embedded devices. OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the ltq-ptm driver which is used to drive the datapath of the DSL line. This only effects the lantiq target supporting xrx200, danube and amazon SoCs from Lantiq/Intel/MaxLinear with the DSL in PTM mode. The DSL driver for the VRX518 is not affected. ATM mode is also not affected. Most VDSL lines use PTM mode and most ADSL lines use ATM mode. OpenWrt is normally running as a single user system, but some services are sandboxed. This vulnerability could allow attackers to escape a ujail sandbox or other contains. This is fixed in OpenWrt 24.10.4. There are no workarounds. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2025-20711 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00422399; Issue ID: MSV-3748. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2025-20722 | In gnss driver, there is a possible out of bounds read due to an integer overflow. In gnss driver, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09920036; Issue ID: MSV-3798. NVD description · AI analysis pending | 5.5 | <1% |
| — | ||
| CVE-2025-20705 | In monitor_hang, there is a possible memory corruption due to use after free. In monitor_hang, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09989078; Issue ID: MSV-3964. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-20696 | In DA, there is a possible out of bounds write due to a missing bounds check. In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09915215; Issue ID: MSV-3801. NVD description · AI analysis pending | 6.8 | <1% |
| — | ||
| CVE-2025-20695 +1 in the same advisory: …20694 | In Bluetooth FW, there is a possible system crash due to an uncaught exception. In Bluetooth FW, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09741871; Issue ID: MSV-3317. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-20693 | In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. In wlan STA driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09812521; Issue ID: MSV-3421. NVD description · AI analysis pending | 6.5 | <1% |
| — |