Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-61876: LuCI DHCP Lease Hostname Cross-Site Scripting
CVE-2026-61876
CVE-2026-61876
Summary
An attacker on the same network can inject malicious code into LuCI's DHCP lease pages, potentially allowing them to take control of an administrator's browser. This vulnerability affects LuCI versions, so update to the latest version to fix the issue. Regularly updating LuCI ensures you have the latest security patches.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| openwrt | luci | All versions |
Original title
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
Original description
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.
nvd CVSS3.1
8.8
nvd CVSS4.0
9.4
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 12 Jul 2026 · Updated: 20 Jul 2026 · First seen: 12 Jul 2026