ZeroHour
Exploit-DBpublished ()ingested

[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting

mediumExploit / PoCimportance 25
AI summary · glm-5.3

Stored cross-site scripting in OpenWrt LuCI via malicious DHCPv6 lease hostnames allows router interface attacks.

Exploit-DB entry 52637 describes a stored cross-site scripting vulnerability in LuCI, the OpenWrt web administration interface. A attacker on the local network can set a malicious hostname that gets stored in DHCPv6 lease data and rendered unsafely in the LuCI UI. When an administrator views the lease status page, the injected script executes in the router's management context.

  • Stored XSS in LuCI via DHCPv6 lease hostname
  • Script runs in router admin interface context
  • Affects OpenWrt deployments with DHCPv6 enabled
Full article

LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting

This source does not provide full text. Read it at exploit-db.com.