openwrt records
145 published records for vendor openwrt.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 2.1%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-787 Out-of-bounds Write43
- CWE-125 Out-of-bounds Read17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-121 Stack-based Buffer Overflow14
- CWE-122 Heap-based Buffer Overflow13
- CWE-20 Improper Input Validation3
The weakness classes this vendor ships most often: where to look.
CWEAll records
145 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
53Plan | CVE-2024-20017Proof of concept | In wlan service, there is a possible out of bounds write due to improper input validation.mediatek · software development kit · CWE-20 | Critical9.8 | — | 46.6% | Mar 3, 2024 |
41Plan | CVE-2019-12272Proof of concept | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web applopenwrt · luci · CWE-78 | Critical9.8 | — | 7.4% | May 23, 2019 |
40Plan | CVE-2020-28951No exploit | libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names.openwrt · openwrt · CWE-416 | Critical9.8 | — | 1.8% | Nov 19, 2020 |
39Monitor | CVE-2025-20654No exploit | In wlan service, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Critical9.8 | — | 0.8% | Apr 7, 2025 |
39Monitor | CVE-2025-20674No exploit | In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check.openwrt · openwrt · CWE-863 | Critical9.8 | — | 0.8% | Jun 1, 2025 |
39Monitor | CVE-2025-20681No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Critical9.8 | — | 0.6% | Jul 7, 2025 |
39Monitor | CVE-2025-20683No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Critical9.8 | — | 0.5% | Jul 7, 2025 |
39Monitor | CVE-2025-20682No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Critical9.8 | — | 0.5% | Jul 7, 2025 |
38Monitor | CVE-2024-54143No exploit | openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionopenwrt · asu · CWE-328 | Critical9.3 | — | 1.8% | Dec 6, 2024 |
38Monitor | CVE-2026-30872No exploit | OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupopenwrt · openwrt · CWE-121 | Critical9.5 | — | 1.1% | Mar 19, 2026 |
38Monitor | CVE-2026-30871No exploit | OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Queryopenwrt · openwrt · CWE-121 | Critical9.5 | — | 0.7% | Mar 19, 2026 |
38Monitor | CVE-2026-62948No exploit | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UIopenwrt · openwrt · CWE-79 | Critical9.6 | — | 0.6% | Jul 15, 2026 |
36Monitor | CVE-2018-11116No exploit | OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call aopenwrt · openwrt · CWE-732 | High8.8 | — | 2.4% | Jun 19, 2018 |
35Monitor | CVE-2021-28961No exploit | applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to injecopenwrt · openwrt · CWE-78 | High8.8 | — | 1.5% | Mar 21, 2021 |
35Monitor | CVE-2019-17367No exploit | OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firopenwrt · openwrt · CWE-352 | High8.8 | — | 0.6% | Oct 18, 2019 |
35Monitor | CVE-2025-20685No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | High8.8 | — | 0.3% | Jul 7, 2025 |
35Monitor | CVE-2025-20686No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | High8.8 | — | 0.3% | Jul 7, 2025 |
35Monitor | CVE-2025-20711No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | High8.8 | — | 0.3% | Oct 14, 2025 |
35Monitor | CVE-2025-20709No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-120 | High8.8 | — | 0.3% | Oct 14, 2025 |
35Monitor | CVE-2025-20710No exploit | In wlan AP driver, there is a possible out of bounds write due to an integer overflow.mediatek · software development kit · CWE-190 | High8.8 | — | 0.3% | Oct 14, 2025 |
35Monitor | CVE-2025-20712No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | High8.8 | — | 0.3% | Oct 14, 2025 |
35Monitor | CVE-2026-20408No exploit | In wlan, there is a possible out of bounds write due to a heap buffer overflow.mediatek · software development kit · CWE-122 | High8.8 | — | 0.3% | Feb 2, 2026 |
35Monitor | CVE-2025-20720No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | High8.8 | — | 0.3% | Oct 14, 2025 |
35Monitor | CVE-2025-20719No exploit | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-121 | High8.8 | — | 0.3% | Oct 14, 2025 |
35Monitor | CVE-2026-20430No exploit | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | High8.8 | — | 0.2% | Mar 2, 2026 |
- CVE-2024-2001753Plan
In wlan service, there is a possible out of bounds write due to improper input validation.
CriticalCVSS 9.8Proof of conceptEPSS 47%mediatek · software development kitMar 3, 2024
- CVE-2019-1227241Plan
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web appl
CriticalCVSS 9.8Proof of conceptEPSS 7%openwrt · luciMay 23, 2019
- CVE-2020-2895140Plan
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names.
CriticalCVSS 9.8No exploitEPSS 2%openwrt · openwrtNov 19, 2020
- CVE-2025-2065439Monitor
In wlan service, there is a possible out of bounds write due to an incorrect bounds check.
CriticalCVSS 9.8No exploitEPSS 1%mediatek · software development kitApr 7, 2025
- CVE-2025-2067439Monitor
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check.
CriticalCVSS 9.8No exploitEPSS 1%openwrt · openwrtJun 1, 2025
- CVE-2025-2068139Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
CriticalCVSS 9.8No exploitEPSS 1%mediatek · software development kitJul 7, 2025
- CVE-2025-2068339Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
CriticalCVSS 9.8No exploitEPSS 1%mediatek · software development kitJul 7, 2025
- CVE-2025-2068239Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
CriticalCVSS 9.8No exploitEPSS 1%mediatek · software development kitJul 7, 2025
- CVE-2024-5414338Monitor
openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection
CriticalCVSS 9.3No exploitEPSS 2%openwrt · asuDec 6, 2024
- CVE-2026-3087238Monitor
OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookup
CriticalCVSS 9.5No exploitEPSS 1%openwrt · openwrtMar 19, 2026
- CVE-2026-3087138Monitor
OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Query
CriticalCVSS 9.5No exploitEPSS 1%openwrt · openwrtMar 19, 2026
- CVE-2026-6294838Monitor
OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
CriticalCVSS 9.6No exploitEPSS 1%openwrt · openwrtJul 15, 2026
- CVE-2018-1111636Monitor
OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call a
HighCVSS 8.8No exploitEPSS 2%openwrt · openwrtJun 19, 2018
- CVE-2021-2896135Monitor
applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to injec
HighCVSS 8.8No exploitEPSS 2%openwrt · openwrtMar 21, 2021
- CVE-2019-1736735Monitor
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, fir
HighCVSS 8.8No exploitEPSS 1%openwrt · openwrtOct 18, 2019
- CVE-2025-2068535Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitJul 7, 2025
- CVE-2025-2068635Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitJul 7, 2025
- CVE-2025-2071135Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitOct 14, 2025
- CVE-2025-2070935Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitOct 14, 2025
- CVE-2025-2071035Monitor
In wlan AP driver, there is a possible out of bounds write due to an integer overflow.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitOct 14, 2025
- CVE-2025-2071235Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitOct 14, 2025
- CVE-2026-2040835Monitor
In wlan, there is a possible out of bounds write due to a heap buffer overflow.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitFeb 2, 2026
- CVE-2025-2072035Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitOct 14, 2025
- CVE-2025-2071935Monitor
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitOct 14, 2025
- CVE-2026-2043035Monitor
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check.
HighCVSS 8.8No exploitEPSS 0%mediatek · software development kitMar 2, 2026