Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.6

CVE-2026-62948: OpenWrt odhcpd/LuCI: Unauthenticated DHCPv6 Client Injects Malicious Code

CVE-2026-62948 CVE-2026-62948
Summary

An attacker can inject malicious code into the OpenWrt admin interface, potentially allowing them to steal sensitive information or take control of the device. This is fixed in version 25.12.5. Users should update to this version to prevent exploitation.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
openwrt openwrt < 25.12.5
Original title
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_w...
Original description
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI rpcd-mod-luci getDHCPLeases displays through htdocs/luci-static/resources/view/status/include/40_dhcp.js and htdocs/luci-static/resources/luci.js dom.append as live HTML in the Active DHCPv6 Leases admin page. This vulnerability is fixed in 25.12.5.
nvd CVSS3.1 9.6
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-117
CWE-150
Published: 15 Jul 2026 · Updated: 20 Jul 2026 · First seen: 15 Jul 2026