VendorsOpenWrtluciany version
Vulnerabilities

OpenWrt LuCI any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2019-12272
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
Published 2019-05-23 · Modified
9.8EPSS 0.074
CVE-2026-32721
LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal
Published 2026-03-19 · Analyzed
8.6EPSS 0.003
CVE-2021-27821
The Web Interface for OpenWRT LuCI version 19.07 and lower has been discovered to have a cross-site scripting vulnerability.
Published 2021-05-25 · Modified
6.1EPSS 0.006