Description
LuCI in OpenWrt 18.06.0 through 18.06.4 allows stored XSS via a crafted SSID.
References (2)
Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/openwrt/luci/commit/bc17ef673f734ea8e7e696ba5735588da9111dcd
Exploit, Patch, Vendor Advisory x_refsource_misc
https://openwrt.org/advisory/2019-11-05-1
Scores
CVSS v3
5.4
EPSS
0.0034
EPSS Percentile
56.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (1)
openwrt/openwrt
18.06.0 - 18.06.4
Published
Jan 26, 2021
Tracked Since
Feb 18, 2026