Known Vulnerabilities for Luci by Openwrt
Listed below are 6 of the newest known vulnerabilities associated with "Luci" by "Openwrt".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-32721 json | LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability i... | Not Provided | 2026-03-19 | 2026-03-25 |
| CVE-2026-4537 json | A vulnerability was determined in Cudy TR1200 R46-2.4.15-20250721-164017. Impacted is the function action_ipsec_conn of the f... | Not Provided | 2026-03-22 | 2026-04-29 |
| CVE-2026-1802 json | A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file l... | Not Provided | 2026-02-03 | 2026-02-23 |
| CVE-2023-24181 json | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi... | 5.4 - MEDIUM | 2023-04-10 | 2023-04-13 |
| CVE-2022-41435 json | OpenWRT LuCI version git-22.140.66206-02913be was discovered to contain a stored cross-site scripting (XSS) vulnerability in ... | 5.4 - MEDIUM | 2022-11-03 | 2022-11-04 |
| CVE-2021-27821 json | The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability w... | 6.1 - MEDIUM | 2021-05-25 | 2021-06-03 |
| CVE-2020-10871 json | ** DISPUTED ** In OpenWrt LuCI git-20.x, remote unauthenticated attackers can retrieve the list of installed packages and ser... | 5.3 - MEDIUM | 2020-03-23 | 2023-11-07 |
| CVE-2019-12272 json | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status ... | 9.8 - CRITICAL | 2019-05-23 | 2020-08-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openwrt | Luci | git-20.078.22902-0ed0d42 | |||
| Application | Openwrt | Luci | git-20.049.11521-bebfe20 | |||
| Application | Openwrt | Luci | 0.9.0 | |||
| Application | Openwrt | Luci | 0.8.8 | |||
| Application | Openwrt | Luci | 0.8.7 | |||
| Application | Openwrt | Luci | 0.8.6 | |||
| Application | Openwrt | Luci | 0.8.5 | |||
| Application | Openwrt | Luci | 0.8.4 | |||
| Application | Openwrt | Luci | 0.8.3 | |||
| Application | Openwrt | Luci | 0.8.2 | |||
| Application | Openwrt | Luci | 0.8.1 | |||
| Application | Openwrt | Luci | 0.8.0 | |||
| Application | Openwrt | Luci | 0.11.1 | |||
| Application | Openwrt | Luci | 0.11.0 | |||
| Application | Openwrt | Luci | 0.10.0 |