Known Vulnerabilities for products from Openwrt
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Openwrt".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-69096 json | Not Provided | 2026-08-03 | 2026-08-03 | |
| CVE-2026-69095 json | Not Provided | 2026-08-03 | 2026-08-03 | |
| CVE-2026-64248 json | Not Provided | 2026-07-24 | 2026-07-24 | |
| CVE-2026-62948 json | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 3... | Not Provided | 2026-07-15 | 2026-07-21 |
| CVE-2026-62947 json | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io authoriz... | Not Provided | 2026-07-15 | 2026-07-21 |
| CVE-2026-59260 json | Not Provided | 2026-07-12 | 2026-07-13 | |
| CVE-2026-55490 json | OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of t... | Not Provided | 2026-07-07 | 2026-07-10 |
| CVE-2026-53317 json | Not Provided | 2026-06-26 | 2026-06-26 | |
| CVE-2026-46368 json | Not Provided | 2026-05-26 | 2026-07-14 | |
| CVE-2026-43173 json | Not Provided | 2026-05-06 | 2026-06-01 | |
| CVE-2026-32721 json | LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability i... | Not Provided | 2026-03-19 | 2026-04-14 |
| CVE-2023-32855 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.7 - MEDIUM | 2023-12-04 | 2023-12-07 |
| CVE-2023-32815 json | In gnss service, there is a possible out of bounds read due to improper input validation. This could lead to local informatio... | 4.4 - MEDIUM | 2023-09-04 | 2023-09-07 |
| CVE-2023-32813 json | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local informati... | 4.4 - MEDIUM | 2023-09-04 | 2023-09-07 |
| CVE-2023-32812 json | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local esclation... | 6.7 - MEDIUM | 2023-09-04 | 2023-09-07 |
| CVE-2023-32806 json | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation... | 6.7 - MEDIUM | 2023-09-04 | 2023-09-07 |
| CVE-2023-24182 json | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a stored cross-site scripting (XSS) vulnerabilit... | 5.4 - MEDIUM | 2023-04-11 | 2023-05-24 |
| CVE-2023-24181 json | LuCI openwrt-22.03 branch git-22.361.69894-438c598 was discovered to contain a reflected cross-site scripting (XSS) vulnerabi... | 5.4 - MEDIUM | 2023-04-10 | 2023-04-13 |
| CVE-2023-20832 json | In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privile... | 6.7 - MEDIUM | 2023-09-04 | 2023-09-07 |
| CVE-2023-20831 json | In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privile... | 6.7 - MEDIUM | 2023-09-04 | 2023-09-07 |