OpenWrt is an embedded Linux distribution and customizable operating system for networking devices such as routers and wireless access points, deployed across a large installed base despite its narrow product scope. The vendor's vulnerability footprint clusters around its core router operating system and related components including the LuCI web interface, LEDE derivative, and the UCI configuration framework, reflecting the diversity of chipsets and embedded platforms that run the distribution. Vulnerabilities affecting OpenWrt skew toward serious outcomes, with a meaningful share reaching critical severity and recurring through memory-safety weakness classes including out-of-bounds reads and writes, buffer overflows, and web-interface input-validation flaws that are characteristic of C-based embedded firmware. The prominence of this vendor in the landscape stems from its presence in countless deployed devices that often operate without timely patching and remain internet-accessible, making OpenWrt disclosures relevant to a broad defensive footprint. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openwrt over time
Signals from CVEs in this vendor scope (146 CVEs).
146 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20017CRITICAL In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. | Mar 4, 2024 | 9.8 | 59 | NO | NO |
CVE-2026-62948CRITICAL OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefil | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-61876HIGH LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCP | Jul 12, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-59260HIGH OpenWrt luci-app-samba4 read ACL grants file.exec permission on /usr/sbin/smbd, allowing authenticated delegated users to execute the Samba daemon with caller-controlled command-li | Jul 12, 2026 | 8.8 | 40 | NO | NO |
CVE-2026-61875HIGH luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers | Jul 12, 2026 | 8.8 | 39 | NO | NO |
CVE-2019-12272CRITICAL In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command inject | May 23, 2019 | 9.8 | 33 | NO | NO |
CVE-2026-30871CRITICAL OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in | Mar 19, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-30872CRITICAL OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in | Mar 19, 2026 | 9.8 | 31 | NO | NO |
CVE-2020-28951CRITICAL libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_s | Nov 19, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-20430HIGH In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional ex | Mar 2, 2026 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (146 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openwrt.
Media articles that mention a CVE ID that affects a product developed by Openwrt — matched by CVE ID, not by vendor name.