CVE-2026-62184

HIGH

luci-app-banip Log Monitor IP Extraction Bypass

Title source: cna
STIX 2.1

Description

luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the login username field, causing banIP to block the wrong target while the real attacker remains unblocked.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-r6hx-4f83-vp8m)
https://github.com/openwrt/luci/security/advisories/GHSA-r6hx-4f83-vp8m
Third Party Advisory third-party-advisory
VulnCheck Advisory: luci-app-banip Log Monitor IP Extraction Bypass
https://www.vulncheck.com/advisories/luci-app-banip-log-monitor-ip-extraction-bypass

Scores

CVSS v3 7.5
EPSS 0.0044
EPSS Percentile 36.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-116
Status published
Products (4)
openwrt/luci < 0.11.1
openwrt/luci d9bbc372e29618a8807b693a1ccf6d0e42cd196c
openwrt/luci-app-banip < 0.11.1
openwrt/luci-app-banip d9bbc372e29618a8807b693a1ccf6d0e42cd196c
Published Jul 13, 2026
Tracked Since Jul 14, 2026