16 Total CVEs
16 AI Analyzed
0 CISA KEV
3 Critical

Profile

0% ended up actively exploited 0 of 16 added to CISA KEV
19% rated critical (CVSS 9.0+) 3 critical, 13 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

16 CVEs in the last 12 months

Products

  • LuCI7
  • luci2
  • luci-app-bmx71
  • openwrt1
  • luci-proto-openvpn1
  • Luci-app-tailscale-community1

6 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-16 of 16 CVEs
CVE-2026-72842
Analyzed
9.9
openwrt luci

An ACL inconsistency in the OpenWrt LuCI LXC application allows authenticated users with low privileges to bypass authorization and execute arbitrary...

2026-08-14
CVE-2026-72841
Analyzed
9.9
openwrt luci

The luci-app-openvpn package for OpenWrt is vulnerable to path traversal during file uploads, enabling authenticated users to write arbitrary files an...

2026-08-14
CVE-2026-72840
Analyzed
8.8
openwrt LuCI

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended o...

2026-08-15
CVE-2026-69096
Analyzed
8.8
openwrt LuCI

OpenWrt luci-app-dockerman (LuCI master and openwrt-25

2026-08-04
CVE-2026-69095
Analyzed
7.5
openwrt luci-app-bmx7

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that...

2026-08-04
CVE-2026-67352
Analyzed
7.6
openwrt LuCI

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject...

2026-08-02
CVE-2026-62948
Analyzed
9.6
openwrt openwrt

A vulnerability in the OpenWrt DHCPv6 client allows for Cross-site Scripting (XSS) via injected lease hostnames displayed in the web administrative in...

2026-07-16
CVE-2026-62184
Analyzed
7.5
openwrt LuCI

luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field posi...

2026-07-14
CVE-2026-61876
Analyzed
8.8
openwrt LuCI

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML mar...

2026-07-14
CVE-2026-61875
Analyzed
8.8
openwrt LuCI

luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMa...

2026-07-17
CVE-2026-59260
Analyzed
8.8
openwrt LuCI

OpenWrt luci-app-samba4 read ACL grants file

2026-07-16
CVE-2026-58000
Analyzed
8.8
openwrt luci-proto-openvpn

luci-proto-openvpn through 0

2026-06-30
CVE-2026-57999
Analyzed
8.8
openwrt Luci-app-tailscale-community

luci-app-tailscale-community contains a command injection vulnerability in the tailscale

2026-06-30
CVE-2026-32721
Analyzed
8.6
openwrt Multiple Products

LuCI is the OpenWrt Configuration Interface

2026-03-20
CVE-2025-62526
Analyzed
7.9
openwrt Multiple Products

OpenWrt Project is a Linux operating system targeting embedded devices

2025-10-22
CVE-2025-62525
Analyzed
7.9
openwrt Multiple Products

OpenWrt Project is a Linux operating system targeting embedded devices

2025-10-22