Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-62948

Опубликовано: 15 июл. 2026
Источник: nvd
CVSS3: 9.6
EPSS Низкий

Описание

OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefiles.c statefiles_write_state6() and statefiles_write_state4() without escaping, allowing newline injection of forged lease lines that LuCI rpcd-mod-luci getDHCPLeases displays through htdocs/luci-static/resources/view/status/include/40_dhcp.js and htdocs/luci-static/resources/luci.js dom.append as live HTML in the Active DHCPv6 Leases admin page. This vulnerability is fixed in 25.12.5.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:*
Версия до 25.12.5 (исключая)

EPSS

Процентиль: 28%
0.00358
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 28%
0.00358
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-79