CVE-2026-61876: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in openwrt luci
Description
CVE-2026-61876 is a critical cross-site scripting (XSS) vulnerability in the OpenWrt LuCI interface. It occurs because DHCPv6 lease hostnames are not properly encoded before being displayed in status tables. An adjacent network attacker can exploit this by sending a DHCPv6 Client FQDN containing malicious script tags, which execute in the administrator's browser when viewing the DHCP lease pages.
CVSS v4.0
Score 9.4critical
Affected software
openwrt
luci
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in OpenWrt's LuCI web interface arises from improper neutralization of input during web page generation. Specifically, DHCPv6 lease hostnames are rendered without proper encoding, allowing injection of HTML markup. This enables an attacker on the adjacent network to craft a DHCPv6 Client FQDN with embedded script tags that execute in the context of the administrator's browser when they access the DHCP lease status page, leading to cross-site scripting.
Potential Impact
Successful exploitation allows an adjacent network attacker to execute arbitrary scripts in the administrator's browser session. This can lead to theft of sensitive information, session hijacking, or other malicious actions within the context of the LuCI web interface. The CVSS 4.0 score of 9.4 reflects high impact on confidentiality, integrity, and availability with low attack complexity and no privileges required.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should limit access to the LuCI interface to trusted networks and avoid viewing DHCP lease pages when untrusted devices are connected to the adjacent network.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-10T21:54:26.760Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Indicators of Compromise
Exploit Source Code
Exploit code for LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting
# Exploit Title: LuCI DHCPv6 - Lease Hostname Stored Cross-Site Scripting # CVE: CVE-2026-61876 # Date: 2026-07-13 # Exploit Author: Mohammed Idrees Banyamer # Author Country: Jordan # Instagram: @banyamer_security # Author GitHub: https://github.com/mbanyamer # Author Blog : https://banyamersecurity.com/blog/ # Vendor Homepage: https://openwrt.org/ # Software Link: https://github.com/openwrt/luci # Affecte... (7213 more characters)
Threat ID: 6a53860e68715ace4310e398
Added to database: 07/12/2026, 12:18:22 UTC
Last enriched: 08/11/2026, 21:08:46 UTC
Last updated: 10/10/2026, 06:48:18 UTC
Views: 414
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.