CVE-2026-62948
OpenWrt odhcpd/LuCI: unauthenticated DHCPv6 client can inject lease-file lines via FQDN hostname → stored XSS in the LuCI admin UI
Description
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI rpcd-mod-luci getDHCPLeases displays through htdocs/luci-static/resources/view/status/include/40_dhcp.js and htdocs/luci-static/resources/luci.js dom.append as live HTML in the Active DHCPv6 Leases admin page. This vulnerability is fixed in 25.12.5.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- MEGANews. Cамые важные события в мире инфосека за августru-ru·Хакер (xakep.ru)· Exploited Dahua Cameras Lazarus
- В OpenWrt исправили критическую уязвимость в DHCPv6-сервереru-ru·Хакер (xakep.ru)· Patch OpenWrt odhcpd ics-ot-iot
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Rooten·The Hacker News· Patch odhcpd rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62948 and every CVE in our database. Create a free account — no credit card required.
Create Free Account