« Volver al listado

Openwrt

Openwrt: vulnerabilidades y CVE

Openwrt tiene 142 vulnerabilidades publicadas, 49 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE142
Últimos 12 meses49
Críticas12
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-62381Media (6.9)0.11%—22 ago 2026
luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate with a 2040-bit RSA key. For a 255-byte signature, the BIT STRING…
CVE-2026-72842Crítica (9.4)0.62%—13 ago 2026
luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management routes without proper authorization checks. Attackers can exploit path…
CVE-2026-66747Crítica (9.3)0.79%—5 ago 2026
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package…
CVE-2026-69096Alta (8.7)3.3%—3 ago 2026
OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) contains an OS command injection vulnerability. The package's read ACL…
CVE-2026-62947Media (4.9)0.52%—15 jul 2026
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authorizes the requested path against the caller's ubus session file ACL before canonicalization, and…
CVE-2026-62948Crítica (9.6)0.58%—15 jul 2026
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and…
CVE-2026-55490Media (6.5)0.68%—7 jul 2026
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash…
CVE-2026-32721Media (4.8)0.29%—19 mar 2026
LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML…
CVE-2026-30874Baja (1.8)0.34%—19 mar 2026
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6, a vulnerability in the hotplug_call function allows an attacker to bypass environment variable filtering and inject…
CVE-2026-30873Baja (2.4)0.65%—19 mar 2026
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to both 24.10.6 and 25.12.1, the jp_get_token function, which performs lexical analysis by breaking input expressions into…
CVE-2026-30872Crítica (9.5)1.1%—19 mar 2026
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function,…
CVE-2026-30871Crítica (9.5)0.67%—19 mar 2026
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue…
CVE-2026-20435Media (4.6)0.12%—2 mar 2026
In preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, if an attacker has physical access to the device, with no additional execution…
CVE-2026-20430Alta (8.8)0.24%—2 mar 2026
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User…
CVE-2026-20419Media (6.5)0.79%—2 feb 2026
In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed.…
CVE-2026-20408Alta (8.8)0.30%—2 feb 2026
In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is…
CVE-2025-20765Media (4.7)0.07%—2 dic 2025
In aee daemon, there is a possible system crash due to a race condition. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for…
CVE-2025-20748Media (6.7)0.17%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20747Media (6.7)0.08%—4 nov 2025
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20746Media (6.7)0.08%—4 nov 2025
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20742Alta (8)0.28%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User…
CVE-2025-20741Media (6.7)0.15%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20739Media (6.7)0.15%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20738Media (6.7)0.15%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20737Alta (7.8)0.15%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…
CVE-2025-20736Media (6.7)0.14%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20735Alta (7.8)0.14%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…
CVE-2025-20734Media (5.3)0.12%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User…
CVE-2025-20733Alta (7.8)0.14%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for…
CVE-2025-20732Media (5.3)0.12%—4 nov 2025
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when…

Otros productos de Openwrt