PT-2026-60254 · Openwrt · Openwrt
CVE-2026-62948
·
Published
2026-07-15
·
Updated
2026-07-21
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenWrt versions prior to 25.12.5
Description
The
odhcpd component writes a DHCPv6 client FQDN option 39 hostname into the /tmp/odhcpd.leases file via the statefiles write state6() and statefiles write state4() functions without proper escaping. This allows for newline injection of forged lease lines. These forged lines are subsequently rendered as live HTML in the Active DHCPv6 Leases admin page by dom.append through htdocs/luci-static/resources/view/status/include/40 dhcp.js and htdocs/luci-static/resources/luci.js via the rpcd-mod-luci getDHCPLeases endpoint.Recommendations
Update OpenWrt to version 25.12.5.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openwrt