Записи openwrt
145 опубликованных записей вендора openwrt.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 2,1 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-787 Out-of-bounds Write43
- CWE-125 Out-of-bounds Read17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-121 Stack-based Buffer Overflow14
- CWE-122 Heap-based Buffer Overflow13
- CWE-20 Improper Input Validation3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
145 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2024-20017Proof of concept | In wlan service, there is a possible out of bounds write due to improper input validation.mediatek · software development kit · CWE-20 | Критическая9,8 | — | 46,6 % | 3 мар. 2024 г. |
41В плане | CVE-2019-12272Proof of concept | In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web applopenwrt · luci · CWE-78 | Критическая9,8 | — | 7,4 % | 23 мая 2019 г. |
40В плане | CVE-2020-28951Эксплойта нет | libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names.openwrt · openwrt · CWE-416 | Критическая9,8 | — | 1,8 % | 19 нояб. 2020 г. |
39Наблюдать | CVE-2025-20654Эксплойта нет | In wlan service, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Критическая9,8 | — | 0,8 % | 7 апр. 2025 г. |
39Наблюдать | CVE-2025-20674Эксплойта нет | In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check.openwrt · openwrt · CWE-863 | Критическая9,8 | — | 0,8 % | 1 июн. 2025 г. |
39Наблюдать | CVE-2025-20681Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Критическая9,8 | — | 0,6 % | 7 июл. 2025 г. |
39Наблюдать | CVE-2025-20683Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Критическая9,8 | — | 0,5 % | 7 июл. 2025 г. |
39Наблюдать | CVE-2025-20682Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Критическая9,8 | — | 0,5 % | 7 июл. 2025 г. |
38Наблюдать | CVE-2024-54143Эксплойта нет | openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injectionopenwrt · asu · CWE-328 | Критическая9,3 | — | 1,8 % | 6 дек. 2024 г. |
38Наблюдать | CVE-2026-30872Эксплойта нет | OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookupopenwrt · openwrt · CWE-121 | Критическая9,5 | — | 1,1 % | 19 мар. 2026 г. |
38Наблюдать | CVE-2026-30871Эксплойта нет | OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Queryopenwrt · openwrt · CWE-121 | Критическая9,5 | — | 0,7 % | 19 мар. 2026 г. |
38Наблюдать | CVE-2026-62948Эксплойта нет | OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UIopenwrt · openwrt · CWE-79 | Критическая9,6 | — | 0,6 % | 15 июл. 2026 г. |
36Наблюдать | CVE-2018-11116Эксплойта нет | OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call aopenwrt · openwrt · CWE-732 | Высокая8,8 | — | 2,4 % | 19 июн. 2018 г. |
35Наблюдать | CVE-2021-28961Эксплойта нет | applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to injecopenwrt · openwrt · CWE-78 | Высокая8,8 | — | 1,5 % | 21 мар. 2021 г. |
35Наблюдать | CVE-2019-17367Эксплойта нет | OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, firopenwrt · openwrt · CWE-352 | Высокая8,8 | — | 0,6 % | 18 окт. 2019 г. |
35Наблюдать | CVE-2025-20685Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | Высокая8,8 | — | 0,3 % | 7 июл. 2025 г. |
35Наблюдать | CVE-2025-20686Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | Высокая8,8 | — | 0,3 % | 7 июл. 2025 г. |
35Наблюдать | CVE-2025-20711Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Высокая8,8 | — | 0,3 % | 14 окт. 2025 г. |
35Наблюдать | CVE-2025-20709Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-120 | Высокая8,8 | — | 0,3 % | 14 окт. 2025 г. |
35Наблюдать | CVE-2025-20710Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an integer overflow.mediatek · software development kit · CWE-190 | Высокая8,8 | — | 0,3 % | 14 окт. 2025 г. |
35Наблюдать | CVE-2025-20712Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | Высокая8,8 | — | 0,3 % | 14 окт. 2025 г. |
35Наблюдать | CVE-2026-20408Эксплойта нет | In wlan, there is a possible out of bounds write due to a heap buffer overflow.mediatek · software development kit · CWE-122 | Высокая8,8 | — | 0,3 % | 2 февр. 2026 г. |
35Наблюдать | CVE-2025-20720Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-122 | Высокая8,8 | — | 0,3 % | 14 окт. 2025 г. |
35Наблюдать | CVE-2025-20719Эксплойта нет | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-121 | Высокая8,8 | — | 0,3 % | 14 окт. 2025 г. |
35Наблюдать | CVE-2026-20430Эксплойта нет | In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check.mediatek · software development kit · CWE-787 | Высокая8,8 | — | 0,2 % | 2 мар. 2026 г. |
- CVE-2024-2001753В плане
In wlan service, there is a possible out of bounds write due to improper input validation.
КритическаяCVSS 9,8Proof of conceptEPSS 47 %mediatek · software development kit3 мар. 2024 г.
- CVE-2019-1227241В плане
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web appl
КритическаяCVSS 9,8Proof of conceptEPSS 7 %openwrt · luci23 мая 2019 г.
- CVE-2020-2895140В плане
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %openwrt · openwrt19 нояб. 2020 г.
- CVE-2025-2065439Наблюдать
In wlan service, there is a possible out of bounds write due to an incorrect bounds check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mediatek · software development kit7 апр. 2025 г.
- CVE-2025-2067439Наблюдать
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openwrt · openwrt1 июн. 2025 г.
- CVE-2025-2068139Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mediatek · software development kit7 июл. 2025 г.
- CVE-2025-2068339Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mediatek · software development kit7 июл. 2025 г.
- CVE-2025-2068239Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mediatek · software development kit7 июл. 2025 г.
- CVE-2024-5414338Наблюдать
openwrt/asu allows build artifact poisoning via truncated SHA-256 hash and command injection
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %openwrt · asu6 дек. 2024 г.
- CVE-2026-3087238Наблюдать
OpenWrt Project has a Stack-based Buffer Overflow vulnerability via IPv6 reverse DNS lookup
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %openwrt · openwrt19 мар. 2026 г.
- CVE-2026-3087138Наблюдать
OpenWrt Project has Stack-based Buffer Overflow in DNS PTR Query
КритическаяCVSS 9,5Эксплойта нетEPSS 1 %openwrt · openwrt19 мар. 2026 г.
- CVE-2026-6294838Наблюдать
OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %openwrt · openwrt15 июл. 2026 г.
- CVE-2018-1111636Наблюдать
OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call a
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %openwrt · openwrt19 июн. 2018 г.
- CVE-2021-2896135Наблюдать
applications/luci-app-ddns/luasrc/model/cbi/ddns/detail.lua in the DDNS package for OpenWrt 19.07 allows remote authenticated users to injec
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %openwrt · openwrt21 мар. 2021 г.
- CVE-2019-1736735Наблюдать
OpenWRT firmware version 18.06.4 is vulnerable to CSRF via wireless/radio0.network1, wireless/radio1.network1, firewall, firewall/zones, fir
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %openwrt · openwrt18 окт. 2019 г.
- CVE-2025-2068535Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit7 июл. 2025 г.
- CVE-2025-2068635Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit7 июл. 2025 г.
- CVE-2025-2071135Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit14 окт. 2025 г.
- CVE-2025-2070935Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit14 окт. 2025 г.
- CVE-2025-2071035Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an integer overflow.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit14 окт. 2025 г.
- CVE-2025-2071235Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit14 окт. 2025 г.
- CVE-2026-2040835Наблюдать
In wlan, there is a possible out of bounds write due to a heap buffer overflow.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit2 февр. 2026 г.
- CVE-2025-2072035Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit14 окт. 2025 г.
- CVE-2025-2071935Наблюдать
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit14 окт. 2025 г.
- CVE-2026-2043035Наблюдать
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %mediatek · software development kit2 мар. 2026 г.