CVE-2026-62948
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI rpcd-mod-luci getDHCPLeases displays through htdocs/luci-static/resources/view/status/include/40_dhcp.js and htdocs/luci-static/resources/luci.js dom.append as live HTML in the Active DHCPv6 Leases admin page. This vulnerability is fixed in 25.12.5.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 0.58%
- CWE
- CWE-79, CWE-117, CWE-150
- Published
- 2026-07-15
- Last modified
- 2026-07-15
Affected products
- openwrt openwrt
Weakness type
Related vulnerabilities
- CVE-2026-87926 — Rizwan17 inventory-management-system Login Page index.php cross site scripting
- CVE-2026-87923 — Rizwan17 inventory-management-system List DBOperation.php cross site scripting
- CVE-2026-87995 — Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-origin
- CVE-2026-54694 — NationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account Takeover
- CVE-2026-18147 — Freeipa: ipa: freeipa/idm: cross-site scripting vulnerability allows arbitrary code execution via crafted url
- CVE-2026-86772 — Snipe-IT 8.6.3 Stored XSS via Department Names
- CVE-2026-87814 — SiYuan before v3.8.2 Stored XSS via Asset Preview
- CVE-2026-87813 — SiYuan before v3.8.2 Stored XSS via unescaped asset filenames