Openwrt

Vendor:

First CVE: Jun 19, 2018 · Active for 8 years

137
Total CVEs
More Total CVEs than 99% of tracked products
15.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Openwrt over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2018
8 years ago
Most Recent CVE
Jul 15, 2026
9 days ago

CVE Severity & Scoring

Openwrt137 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local70 (51.1%)
Network36 (26.3%)
Unknown0 (0.0%)
Physical9 (6.6%)
Adjacent Network22 (16.1%)
Attack Complexity
Low130 (94.9%)
High7 (5.1%)
Unknown0 (0.0%)
User Interaction
None119 (86.9%)
Unknown0 (0.0%)
Required18 (13.1%)
Privileges Required
Low38 (27.7%)
High46 (33.6%)
None53 (38.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (137 CVEs).

137 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed.
Mar 4, 20249.859NONO
OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefil
Jul 15, 20269.641NONO
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in
Mar 19, 20269.832NONO
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in
Mar 19, 20269.831NONO
libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_s
Nov 19, 20209.831NONO
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional ex
Mar 2, 20268.830NONO
OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the l
Oct 22, 20258.830NONO
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execut
Jun 2, 20259.830NONO
OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated a
Jul 7, 20266.529NONO
In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution p
Feb 2, 20268.829NONO

Exploit Exposure

Signals from CVEs in this product scope (137 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (137 CVEs).

Media Mentions

Signals from CVEs in this product scope (137 CVEs).

Top CNAs Publishing CVEs For Openwrt

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
23.05.086.70.1%00
23.05236.50.2%00
22.03.545.50.1%00
22.03.315.40.6%00
22.03.017.51.0%00
21.02.135.40.5%00
21.02.0976.80.7%00
21.0245.50.1%00
19.07.0906.90.8%00
18.06.445.70.7%00
1818.80.6%00
15.05.125.90.8%00