Openwrt
Vendor:
First CVE: Jun 19, 2018 · Active for 8 years
137
Total CVEs
More Total CVEs than 99% of tracked products
15.2
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Openwrt over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2018
8 years ago
Most Recent CVE
Jul 15, 2026
9 days ago
CVE Severity & Scoring
Openwrt137 CVEs
65%
26%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local70 (51.1%)
Network36 (26.3%)
Unknown0 (0.0%)
Physical9 (6.6%)
Adjacent Network22 (16.1%)
Attack Complexity
Low130 (94.9%)
High7 (5.1%)
Unknown0 (0.0%)
User Interaction
None119 (86.9%)
Unknown0 (0.0%)
Required18 (13.1%)
Privileges Required
Low38 (27.7%)
High46 (33.6%)
None53 (38.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (137 CVEs).
137 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20017CRITICAL In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. | Mar 4, 2024 | 9.8 | 59 | NO | NO |
CVE-2026-62948CRITICAL OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odhcpd.leases through src/statefil | Jul 15, 2026 | 9.6 | 41 | NO | NO |
CVE-2026-30871CRITICAL OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in | Mar 19, 2026 | 9.8 | 32 | NO | NO |
CVE-2026-30872CRITICAL OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in | Mar 19, 2026 | 9.8 | 31 | NO | NO |
CVE-2020-28951CRITICAL libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_s | Nov 19, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-20430HIGH In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional ex | Mar 2, 2026 | 8.8 | 30 | NO | NO |
CVE-2025-62525HIGH OpenWrt Project is a Linux operating system targeting embedded devices. Prior to version 24.10.4, local users could read and write arbitrary kernel memory using the ioctls of the l | Oct 22, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-20674CRITICAL In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execut | Jun 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2026-55490MEDIUM OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated a | Jul 7, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-20408HIGH In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution p | Feb 2, 2026 | 8.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (137 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (137 CVEs).
Media Mentions
Signals from CVEs in this product scope (137 CVEs).
Top CNAs Publishing CVEs For Openwrt
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 23.05.0 | 8 | 6.7 | 0.1% | 0 | 0 |
| 23.05 | 23 | 6.5 | 0.2% | 0 | 0 |
| 22.03.5 | 4 | 5.5 | 0.1% | 0 | 0 |
| 22.03.3 | 1 | 5.4 | 0.6% | 0 | 0 |
| 22.03.0 | 1 | 7.5 | 1.0% | 0 | 0 |
| 21.02.1 | 3 | 5.4 | 0.5% | 0 | 0 |
| 21.02.0 | 97 | 6.8 | 0.7% | 0 | 0 |
| 21.02 | 4 | 5.5 | 0.1% | 0 | 0 |
| 19.07.0 | 90 | 6.9 | 0.8% | 0 | 0 |
| 18.06.4 | 4 | 5.7 | 0.7% | 0 | 0 |
| 18 | 1 | 8.8 | 0.6% | 0 | 0 |
| 15.05.1 | 2 | 5.9 | 0.8% | 0 | 0 |