CVE-2026-62381: Heap-based Buffer Overflow in openwrt luci
Description
CVE-2026-62381 is a heap-based buffer overflow vulnerability in the luci-lib-px5g component of OpenWrt's LuCI interface. It occurs in the ASN.1 encoding routine when signing certificates with a 2040-bit RSA key, causing a one-byte overflow beyond the allocated heap buffer. This flaw is reachable via the Lua interface function create_selfsigned(). The vulnerability affects OpenWrt release branches from 18.06 through 25.12 and has been removed from the master branch. The CVSS 4.0 score is 6.9, indicating medium severity.
CVSS v4.0
Score 6.9medium
Affected software
openwrt
luci
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the native ASN.1 encoding routine asn1_add_obj (x509write.c) of luci-lib-px5g, where the allocation for a BIT STRING during certificate signing underestimates the required buffer size by one byte. Specifically, for a 255-byte signature, the DER length encoding calculation leads to a 259-byte allocation, but 260 bytes are written due to an additional unused-bits byte and DER length octet. This heap overflow can be triggered through the exported Lua interface function create_selfsigned(). The vulnerability is present in OpenWrt versions from 18.06 through 25.12 but is absent in the master branch where luci-lib-px5g was removed instead of patched.
Potential Impact
The heap-based buffer overflow can lead to memory corruption, potentially causing crashes or other undefined behavior. Exploitability depends on the embedding application using the vulnerable Lua interface. The CVSS 4.0 vector indicates local attack vector, low attack complexity, no privileges required but low user interaction, and high impact on availability. There are no known exploits in the wild at this time.
Mitigation Recommendations
No official patch is currently available as the vulnerable code was removed from the master branch rather than patched. Users should upgrade to OpenWrt versions that do not include luci-lib-px5g (master branch or later). Until then, avoid using the create_selfsigned() Lua interface or restrict access to it to trusted users only. Monitor vendor advisories for any future patches or official fixes.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-13T22:40:54.412Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a899b9bacd9273b49087875
Added to database: 08/22/2026, 12:52:43 UTC
Last enriched: 09/11/2026, 02:02:57 UTC
Last updated: 10/06/2026, 18:48:23 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.