---
id: CVE-2021-33425
title: >-
  A stored cross-site scripting (XSS) vulnerability was discovered in the Web
  Interface for OpenWRT LuCI version 19.07 which allows attackers to inject
  arbitrary Javascript in the OpenWRT Hostname via the Hostname Change
  operation.
summary: >-
  A stored cross-site scripting (XSS) vulnerability was discovered in the Web
  Interface for OpenWRT LuCI version 19.07 which allows attackers to inject
  arbitrary Javascript in the OpenWRT Hostname via the Hostname Change
  operation.
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: openwrt
product: openwrt
affected:
  - openwrt = 19.07.0
published: '2021-05-25'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-33425'
references:
  - url: 'http://www.openwall.com/lists/oss-security/2021/11/09/1'
    label: cve@mitre.org
  - url: 'http://openwrt.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2021/11/09/1'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0051
epssPercentile: 0.40899
ingestedAt: '2026-07-06T01:08:16.745Z'
---

## Overview

A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.

## Affected

- `openwrt = 19.07.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
