Description
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the login username field, causing banIP to block the wrong target while the real attacker remains unblocked.
References (3)
Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-r6hx-4f83-vp8m)
https://github.com/openwrt/luci/security/advisories/GHSA-r6hx-4f83-vp8m
Patch patch
Patch Commit
https://github.com/openwrt/luci/commit/d9bbc372e29618a8807b693a1ccf6d0e42cd196c
Third Party Advisory third-party-advisory
VulnCheck Advisory: luci-app-banip Log Monitor IP Extraction Bypass
https://www.vulncheck.com/advisories/luci-app-banip-log-monitor-ip-extraction-bypass
Scores
CVSS v3
7.5
EPSS
0.0044
EPSS Percentile
36.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-116
Status
published
Products (4)
openwrt/luci
< 0.11.1
openwrt/luci
d9bbc372e29618a8807b693a1ccf6d0e42cd196c
openwrt/luci-app-banip
< 0.11.1
openwrt/luci-app-banip
d9bbc372e29618a8807b693a1ccf6d0e42cd196c
Published
Jul 13, 2026
Tracked Since
Jul 14, 2026