{"schema_version":1,"title":"OpenWrt vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in OpenWrt: 2 in the last 7 days and 17 in the last 90 days, 3 of them critical and 0 exploited in the wild. The most recent, CVE-2026-55897, was published on 21 September 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/openwrt","json_url":"https://junglewise.ai/threats/vendors/openwrt.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/openwrt","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":10,"all_time":17,"critical":3,"exploited":0,"last_7_days":2,"last_30_days":2,"last_90_days":17,"last_365_days":17},"latest":[{"cve":"CVE-2026-55897","cvss":8.8,"epss":0.0065,"slug":"cve-2026-55897-luci-app-advanced-reboot-is-a-luci-web-interface-application-for","title":"OpenWrt luci-app-advanced-reboot privilege escalation via rpcd ACL","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:26.67+00:00","url":"https://junglewise.ai/threats/cve-2026-55897-luci-app-advanced-reboot-is-a-luci-web-interface-application-for"},{"cve":"CVE-2026-55159","cvss":8.8,"epss":0.0095,"slug":"cve-2026-55159-luci-app-adblock-fast-a-webui-for-fast-lightweight-dns-based-ad","title":"luci-app-adblock-fast command injection in RPC cron entry","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:26.5+00:00","url":"https://junglewise.ai/threats/cve-2026-55159-luci-app-adblock-fast-a-webui-for-fast-lightweight-dns-based-ad"},{"cve":"CVE-2026-62381","cvss":6.6,"epss":0.001,"slug":"cve-2026-62381-openwrt-luci-heap-buffer-overflow-in-asn-1-certificate-signing","title":"OpenWrt LuCI heap buffer overflow in ASN.1 certificate signing","severity":"medium","exploited":false,"published_at":"2026-08-22T13:16:39.957+00:00","url":"https://junglewise.ai/threats/cve-2026-62381-openwrt-luci-heap-buffer-overflow-in-asn-1-certificate-signing"},{"cve":"CVE-2026-72842","cvss":9.9,"epss":0.0062,"slug":"cve-2026-72842-openwrt-luci-app-lxc-acl-bypass-in-container-management","title":"OpenWrt luci-app-lxc ACL bypass in container management","severity":"critical","exploited":false,"published_at":"2026-08-13T22:17:23.977+00:00","url":"https://junglewise.ai/threats/cve-2026-72842-openwrt-luci-app-lxc-acl-bypass-in-container-management"},{"cve":"CVE-2026-72841","cvss":9.9,"epss":0.0062,"slug":"cve-2026-72841-openwrt-luci-app-openvpn-path-traversal-and-arbitrary-file-write","title":"OpenWrt luci-app-openvpn path traversal and arbitrary file write","severity":"critical","exploited":false,"published_at":"2026-08-13T22:17:23.813+00:00","url":"https://junglewise.ai/threats/cve-2026-72841-openwrt-luci-app-openvpn-path-traversal-and-arbitrary-file-write"},{"cve":"CVE-2026-72840","cvss":8.8,"epss":0.0044,"slug":"cve-2026-72840-openwrt-luci-mount-configuration-acl-permission-escalation","title":"OpenWrt LuCI mount configuration ACL permission escalation","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:23.64+00:00","url":"https://junglewise.ai/threats/cve-2026-72840-openwrt-luci-mount-configuration-acl-permission-escalation"},{"cve":"CVE-2026-68583","cvss":5.4,"epss":0.0024,"slug":"cve-2026-68583-openwrt-luci-adblock-fast-stored-xss-in-blocklist-name","title":"OpenWrt LuCI AdBlock Fast stored XSS in blocklist name","severity":"medium","exploited":false,"published_at":"2026-08-02T13:16:54.377+00:00","url":"https://junglewise.ai/threats/cve-2026-68583-openwrt-luci-adblock-fast-stored-xss-in-blocklist-name"},{"cve":"CVE-2026-62947","cvss":4.9,"slug":"cve-2026-62947-openwrt-cgi-io-path-traversal-in-cgi-download-and-cgi-exec","title":"OpenWrt cgi-io path traversal in cgi-download and cgi-exec","severity":"medium","exploited":false,"published_at":"2026-07-15T19:18:38.533+00:00","url":"https://junglewise.ai/threats/cve-2026-62947-openwrt-cgi-io-path-traversal-in-cgi-download-and-cgi-exec"},{"cve":"CVE-2026-62948","cvss":9.6,"slug":"cve-2026-62948-openwrt-odhcpd-and-luci-stored-xss-via-dhcpv6-hostname-injection","title":"OpenWrt odhcpd and LuCI stored XSS via DHCPv6 hostname injection","severity":"critical","exploited":false,"published_at":"2026-07-15T18:16:50.293+00:00","url":"https://junglewise.ai/threats/cve-2026-62948-openwrt-odhcpd-and-luci-stored-xss-via-dhcpv6-hostname-injection"},{"cve":"CVE-2026-62184","cvss":7.5,"slug":"cve-2026-62184-openwrt-luci-app-banip-improper-input-validation-in-log-parser","title":"OpenWrt luci-app-banip improper input validation in log parser","severity":"high","exploited":false,"published_at":"2026-07-13T22:16:49.31+00:00","url":"https://junglewise.ai/threats/cve-2026-62184-openwrt-luci-app-banip-improper-input-validation-in-log-parser"},{"cve":"CVE-2026-61876","cvss":8.8,"slug":"cve-2026-61876-openwrt-luci-stored-xss-in-dhcpv6-lease-status-tables","title":"OpenWrt LuCI stored XSS in DHCPv6 lease status tables","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:46.4+00:00","url":"https://junglewise.ai/threats/cve-2026-61876-openwrt-luci-stored-xss-in-dhcpv6-lease-status-tables"},{"cve":"CVE-2026-61875","cvss":8.8,"slug":"cve-2026-61875-openwrt-luci-app-upnp-stored-xss-via-upnp-port-mapping","title":"OpenWrt luci-app-upnp stored XSS via UPnP port mapping description","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-61875-openwrt-luci-app-upnp-stored-xss-via-upnp-port-mapping"},{"cve":"CVE-2026-59260","cvss":8.8,"slug":"cve-2026-59260-openwrt-luci-app-samba4-privilege-escalation-in-smbd-acl","title":"OpenWrt luci-app-samba4 privilege escalation in smbd ACL","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:45.977+00:00","url":"https://junglewise.ai/threats/cve-2026-59260-openwrt-luci-app-samba4-privilege-escalation-in-smbd-acl"},{"cve":"CVE-2026-55490","cvss":6.5,"slug":"cve-2026-55490-openwrt-emergency-access-daemon-integer-underflow-in-handle-send","title":"OpenWrt Emergency Access Daemon integer underflow in handle_send_a","severity":"medium","exploited":false,"published_at":"2026-07-07T22:16:54.06+00:00","url":"https://junglewise.ai/threats/cve-2026-55490-openwrt-emergency-access-daemon-integer-underflow-in-handle-send"},{"cve":"CVE-2026-58652","cvss":7.5,"slug":"cve-2026-58652-openwrt-luci-app-travelmate-privilege-escalation-to-root-via-uci","title":"OpenWrt luci-app-travelmate privilege escalation to root via UCI script parameter","severity":"high","exploited":false,"published_at":"2026-07-02T13:17:00.3+00:00","url":"https://junglewise.ai/threats/cve-2026-58652-openwrt-luci-app-travelmate-privilege-escalation-to-root-via-uci"},{"cve":"CVE-2026-58000","cvss":8.8,"slug":"cve-2026-58000-openwrt-luci-proto-openvpn-command-injection-in-generatekey","title":"OpenWrt luci-proto-openvpn command injection in generateKey","severity":"high","exploited":false,"published_at":"2026-06-29T19:16:42.993+00:00","url":"https://junglewise.ai/threats/cve-2026-58000-openwrt-luci-proto-openvpn-command-injection-in-generatekey"},{"cve":"CVE-2026-57999","cvss":8.8,"slug":"cve-2026-57999-openwrt-luci-app-tailscale-community-command-injection-in-do","title":"OpenWrt luci-app-tailscale-community command injection in do_login RPC","severity":"high","exploited":false,"published_at":"2026-06-29T19:16:42.857+00:00","url":"https://junglewise.ai/threats/cve-2026-57999-openwrt-luci-app-tailscale-community-command-injection-in-do"}],"vendor":{"hub":true,"name":"OpenWrt","slug":"openwrt","homepage":"https://openwrt.org/","description":"An open-source project providing a Linux-based operating system for embedded devices and routers.","url":"https://junglewise.ai/threats/vendors/openwrt"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":4},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":2,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":2}],"most_severe":[{"cve":"CVE-2026-72842","cvss":9.9,"epss":0.0062,"slug":"cve-2026-72842-openwrt-luci-app-lxc-acl-bypass-in-container-management","title":"OpenWrt luci-app-lxc ACL bypass in container management","severity":"critical","exploited":false,"published_at":"2026-08-13T22:17:23.977+00:00","url":"https://junglewise.ai/threats/cve-2026-72842-openwrt-luci-app-lxc-acl-bypass-in-container-management"},{"cve":"CVE-2026-72841","cvss":9.9,"epss":0.0062,"slug":"cve-2026-72841-openwrt-luci-app-openvpn-path-traversal-and-arbitrary-file-write","title":"OpenWrt luci-app-openvpn path traversal and arbitrary file write","severity":"critical","exploited":false,"published_at":"2026-08-13T22:17:23.813+00:00","url":"https://junglewise.ai/threats/cve-2026-72841-openwrt-luci-app-openvpn-path-traversal-and-arbitrary-file-write"},{"cve":"CVE-2026-62948","cvss":9.6,"slug":"cve-2026-62948-openwrt-odhcpd-and-luci-stored-xss-via-dhcpv6-hostname-injection","title":"OpenWrt odhcpd and LuCI stored XSS via DHCPv6 hostname injection","severity":"critical","exploited":false,"published_at":"2026-07-15T18:16:50.293+00:00","url":"https://junglewise.ai/threats/cve-2026-62948-openwrt-odhcpd-and-luci-stored-xss-via-dhcpv6-hostname-injection"},{"cve":"CVE-2026-55159","cvss":8.8,"epss":0.0095,"slug":"cve-2026-55159-luci-app-adblock-fast-a-webui-for-fast-lightweight-dns-based-ad","title":"luci-app-adblock-fast command injection in RPC cron entry","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:26.5+00:00","url":"https://junglewise.ai/threats/cve-2026-55159-luci-app-adblock-fast-a-webui-for-fast-lightweight-dns-based-ad"},{"cve":"CVE-2026-55897","cvss":8.8,"epss":0.0065,"slug":"cve-2026-55897-luci-app-advanced-reboot-is-a-luci-web-interface-application-for","title":"OpenWrt luci-app-advanced-reboot privilege escalation via rpcd ACL","severity":"high","exploited":false,"published_at":"2026-09-21T20:17:26.67+00:00","url":"https://junglewise.ai/threats/cve-2026-55897-luci-app-advanced-reboot-is-a-luci-web-interface-application-for"},{"cve":"CVE-2026-72840","cvss":8.8,"epss":0.0044,"slug":"cve-2026-72840-openwrt-luci-mount-configuration-acl-permission-escalation","title":"OpenWrt LuCI mount configuration ACL permission escalation","severity":"high","exploited":false,"published_at":"2026-08-13T22:17:23.64+00:00","url":"https://junglewise.ai/threats/cve-2026-72840-openwrt-luci-mount-configuration-acl-permission-escalation"},{"cve":"CVE-2026-61876","cvss":8.8,"slug":"cve-2026-61876-openwrt-luci-stored-xss-in-dhcpv6-lease-status-tables","title":"OpenWrt LuCI stored XSS in DHCPv6 lease status tables","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:46.4+00:00","url":"https://junglewise.ai/threats/cve-2026-61876-openwrt-luci-stored-xss-in-dhcpv6-lease-status-tables"},{"cve":"CVE-2026-61875","cvss":8.8,"slug":"cve-2026-61875-openwrt-luci-app-upnp-stored-xss-via-upnp-port-mapping","title":"OpenWrt luci-app-upnp stored XSS via UPnP port mapping description","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:46.26+00:00","url":"https://junglewise.ai/threats/cve-2026-61875-openwrt-luci-app-upnp-stored-xss-via-upnp-port-mapping"},{"cve":"CVE-2026-59260","cvss":8.8,"slug":"cve-2026-59260-openwrt-luci-app-samba4-privilege-escalation-in-smbd-acl","title":"OpenWrt luci-app-samba4 privilege escalation in smbd ACL","severity":"high","exploited":false,"published_at":"2026-07-12T12:16:45.977+00:00","url":"https://junglewise.ai/threats/cve-2026-59260-openwrt-luci-app-samba4-privilege-escalation-in-smbd-acl"},{"cve":"CVE-2026-58000","cvss":8.8,"slug":"cve-2026-58000-openwrt-luci-proto-openvpn-command-injection-in-generatekey","title":"OpenWrt luci-proto-openvpn command injection in generateKey","severity":"high","exploited":false,"published_at":"2026-06-29T19:16:42.993+00:00","url":"https://junglewise.ai/threats/cve-2026-58000-openwrt-luci-proto-openvpn-command-injection-in-generatekey"}],"generated_at":"2026-09-26T12:07:00.15149+00:00","technologies":[{"name":"OpenWrt LuCI","slug":"luci","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/luci"},{"name":"OpenWrt","slug":"openwrt","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/openwrt"}]}