VulnSea

openwrt has 5 CVEs on record between 2021 and 2026. 3 were published in the last 90 days. The median CVSS is 8.8 (high). None have a confirmed exploitation report. Most affected products: luci (3), luci-app-adblock-fast (1), openwrt (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
8.8
Publish → KEV
Last 90 days
3 prev 0

Products

  • luci 3
  • luci-app-adblock-fast 1
  • openwrt 1
5
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

openwrt vulnerabilities

CVEs affecting openwrt, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-55897High· 8.8PoC
yesterday

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI

luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router into an alternative firmware partition or perform reboot operations directly from the web UI. Prior to 1.1.2-6, the lu…

Midnightopenwrt · lucivia NVD
CVE-2026-55159High· 8.8
yesterday

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound

luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, or unbound. Prior to 1.2.4-2, the luci.adblock-fast.setCronEntry RPC method accepts an entry argument containing carr…

Twilightopenwrt · luci-app-adblock-fastvia NVD
CVE-2026-72840High· 8.8PoC
1mo ago

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended only for mount configuration. Authenticated users with only the mount-configuration ACL …

Midnightopenwrt · luciEPSS 0.38%via NVD
CVE-2021-33425Medium· 5.4
5y ago

A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.

A stored cross-site scripting (XSS) vulnerability was discovered in the Web Interface for OpenWRT LuCI version 19.07 which allows attackers to inject arbitrary Javascript in the OpenWRT Hostname via the Hostname Change operation.

Sunlitopenwrt · openwrtEPSS 0.51%via NVD
CVE-2021-27821Medium· 6.1
5y ago

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability which can lead to attackers carrying out arbitrary code execution.

The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability which can lead to attackers carrying out arbitrary code execution.

Sunlitopenwrt · luciEPSS 0.59%via NVD
openwrt vulnerabilities (CVEs) · VulnSea