Openwrt
Openwrt: vulnerabilidades y CVE
Openwrt tiene 142 vulnerabilidades publicadas, 49 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE142
Últimos 12 meses49
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-62381 | Media (6.9) | 0.11% | — | 22 ago 2026 | luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING… |
| CVE-2026-72842 | Crítica (9.4) | 0.62% | — | 13 ago 2026 | luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path… |
| CVE-2026-66747 | Crítica (9.3) | 0.79% | — | 5 ago 2026 | Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package… |
| CVE-2026-69096 | Alta (8.7) | 3.3% | — | 3 ago 2026 | OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL… |
| CVE-2026-62947 | Media (4.9) | 0.52% | — | 15 jul 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and… |
| CVE-2026-62948 | Crítica (9.6) | 0.58% | — | 15 jul 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and… |
| CVE-2026-55490 | Media (6.5) | 0.68% | — | 7 jul 2026 | OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash… |
| CVE-2026-32721 | Media (4.8) | 0.29% | — | 19 mar 2026 | LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML… |
| CVE-2026-30874 | Baja (1.8) | 0.34% | — | 19 mar 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject… |
| CVE-2026-30873 | Baja (2.4) | 0.65% | — | 19 mar 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, the jp_get_token function, which performs lexical analysis by breaking input expressions into… |
| CVE-2026-30872 | Crítica (9.5) | 1.1% | — | 19 mar 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function,… |
| CVE-2026-30871 | Crítica (9.5) | 0.67% | — | 19 mar 2026 | OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue… |
| CVE-2026-20435 | Media (4.6) | 0.12% | — | 2 mar 2026 | In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution… |
| CVE-2026-20430 | Alta (8.8) | 0.24% | — | 2 mar 2026 | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User… |
| CVE-2026-20419 | Media (6.5) | 0.79% | — | 2 feb 2026 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed.… |
| CVE-2026-20408 | Alta (8.8) | 0.30% | — | 2 feb 2026 | In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is… |
| CVE-2025-20765 | Media (4.7) | 0.07% | — | 2 dic 2025 | In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for… |
| CVE-2025-20748 | Media (6.7) | 0.17% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20747 | Media (6.7) | 0.08% | — | 4 nov 2025 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20746 | Media (6.7) | 0.08% | — | 4 nov 2025 | In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20742 | Alta (8) | 0.28% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User… |
| CVE-2025-20741 | Media (6.7) | 0.15% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20739 | Media (6.7) | 0.15% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20738 | Media (6.7) | 0.15% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20737 | Alta (7.8) | 0.15% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… |
| CVE-2025-20736 | Media (6.7) | 0.14% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20735 | Alta (7.8) | 0.14% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… |
| CVE-2025-20734 | Media (5.3) | 0.12% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2025-20733 | Alta (7.8) | 0.14% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… |
| CVE-2025-20732 | Media (5.3) | 0.12% | — | 4 nov 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when… |