Vulnerabilidades em openwrt
24 resultadosAnálise Vexday
OpenWrt apresenta 18 vulnerabilidades catalogadas, com concentração recente de 10 divulgações nos últimos 90 dias, indicando pressão contínua de correções. A fraqueza dominante é XSS (CWE-79), típica de interfaces web, com 5 vulnerabilidades críticas que demandam atenção imediata. Não há evidências de exploração ativa em wild (KEV), mas o volume e recência sugerem risco substancial para ambientes que não mantêm patches atualizados.
CVE-2026-30872CRITICALOpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupEPSS 2.2%CVE-2024-54143CRITICALopenwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionEPSS 1.9%CVE-2026-69096HIGHOpenWrt luci-app-dockerman Read ACL Remote Code ExecutionEPSS 1.7%CVE-2026-58000HIGHluci-proto-openvpn - Command Injection via cl_meta Parameter in generateKeyEPSS 1.4%CVE-2026-30871CRITICALOpenWrt Project has Stack-based Buffer Overflow in DNS PTR QueryEPSS 1.2%CVE-2026-57999HIGHluci-app-tailscale-community - Command Injection via tailscale.do_login RPCEPSS 1.2%CVE-2026-55490MEDIUMOpenWrt: EAD Integer Underflow → Pre-Auth Denial of ServiceEPSS 1.0%CVE-2019-5101MEDIUMAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting toEPSS 0.8%CVE-2019-5102MEDIUMAn exploitable information leak vulnerability exists in the ustream-ssl library of OpenWrt, versions 18.06.4 and 15.05.1. When connecting toEPSS 0.8%CVE-2026-59260HIGHOpenWrt luci-app-samba4 read ACL remote code execution via smbdEPSS 0.7%CVE-2026-69095HIGHOpenWrt luci-app-bmx7 Path Traversal via bmx7-infoEPSS 0.6%CVE-2026-30873LOWOpenWrt Project jsonpath: Memory leak when processing strings, labels, and regexp tokensEPSS 0.5%CVE-2026-58652HIGHluci-app-travelmate - Arbitrary Command Execution via UCI Script ParameterEPSS 0.5%CVE-2026-62184HIGHluci-app-banip Log Monitor IP Extraction BypassEPSS 0.4%CVE-2026-62947MEDIUMOpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-downloadEPSS 0.4%CVE-2026-62948CRITICALOpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UIEPSS 0.4%CVE-2026-30874LOWOpenWrt procd PATH Environment Variable Filter Bypass via Incorrect String Comparison Leads to Privilege EscalationEPSS 0.3%CVE-2026-61875HIGHluci-app-upnp Stored XSS via UPnP Port Mapping DescriptionEPSS 0.3%CVE-2025-62526HIGHOpenWrt ubusd vulnerable to heap buffer overflowEPSS 0.2%CVE-2026-32721HIGHLuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modalEPSS 0.2%