Vulnerabilities
Vulnerable Software
Openwrt:  >> Openwrt  >> 17.01.0  Security Vulnerabilities
Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.
CVSS Score
7.5
EPSS Score
0.002
Published
2022-09-19
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.
CVSS Score
9.8
EPSS Score
0.005
Published
2020-11-19
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
CVSS Score
6.1
EPSS Score
0.003
Published
2018-11-28


Contact Us

Shodan ® - All rights reserved