ZeroHour

Search: “openwrt”

11 stories

[dos] LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting

Stored cross-site scripting in OpenWrt LuCI via malicious DHCPv6 lease hostnames allows router interface attacks.

Exploit-DB entry 52637 describes a stored cross-site scripting vulnerability in LuCI, the OpenWrt web administration interface. A attacker on the local network can set a malicious hostname that gets stored in DHCPv6 lease data and rendered unsafely in the LuCI UI. When an administrator views the lease status page, the injected script executes in the router's management context.

Exploit-DB · Aug 11, 2026Exploit / PoC

New KATARU IoT Malware Packs Linux Privilege Escalation Exploits and Mirai-Style DDoS Attacks

Nozomi Networks identified KATARU, a new Mirai-style IoT botnet delivered via Telnet brute force that uses Linux privilege-escalation exploits and encrypted C2 for DDoS floods.

Nozomi Networks identified KATARU in August after a Telnet password-guessing attack against a honeypot retrieved an ARM payload. The malware attempts exploits for CVE-2026-46300 (Fragnesia), CVE-2026-43284 (DirtyFrag), and CVE-2026-31431 (Copy Fail), plus a cgroup v1 release_agent escape, and persists via systemd services, cron tasks, rc scripts, OpenWrt hooks, and Android boot locations. Its C2 uses X25519 key exchange with ChaCha20-Poly1305 encryption and supports TCP, UDP, ICMP, HTTP, QUIC, and DNS floods, plus SSH brute forcing and command execution; embedded exploit shellcode in the ARM build targeted x86, suggesting untested copied code.