Vulnerabilities (CVE)

Filtered by vendor Openwrt Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-28951 1 Openwrt 1 Openwrt 2020-12-02 10.0 HIGH 9.8 CRITICAL
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
CVE-2019-12272 1 Openwrt 1 Luci 2020-08-24 7.5 HIGH 9.8 CRITICAL
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.