PT-2026-60254 · Openwrt · Openwrt

CVE-2026-62948

·

Published

2026-07-15

·

Updated

2026-07-21

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenWrt versions prior to 25.12.5
Description The odhcpd component writes a DHCPv6 client FQDN option 39 hostname into the /tmp/odhcpd.leases file via the statefiles write state6() and statefiles write state4() functions without proper escaping. This allows for newline injection of forged lease lines. These forged lines are subsequently rendered as live HTML in the Active DHCPv6 Leases admin page by dom.append through htdocs/luci-static/resources/view/status/include/40 dhcp.js and htdocs/luci-static/resources/luci.js via the rpcd-mod-luci getDHCPLeases endpoint.
Recommendations Update OpenWrt to version 25.12.5.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-62948
GHSA-HHMC-92HW-535F

Affected Products

Openwrt