Security advisories

This page lists vulnerabilities affecting components directly maintained by the OpenWrt project. Issues in third-party components are backported into the supported releases when they apply, but are not enumerated here — see the upstream projects for those.

Additional advisories are published as GitHub Security Advisories on individual project repositories under github.com/openwrt (notably openwrt/asu and other components hosted there). When an issue is disclosed via the GitHub Security Advisory workflow rather than the wiki, it is linked here once published — but the GitHub repository pages are the authoritative source for those.

For the project’s overall security policy and how to report a vulnerability, see Security.

DateCVESummary
CVE-2025-14282Dropbear privilege escalation via Unix domain socket forwarding
CVE-2025-62526ubusd: heap buffer overflow
CVE-2025-62525ltq-ptm: local privilege escalation
CVE-2024-54143OpenWrt Attended SysUpgrade server: Build artifact poisoning via truncated SHA-256 hash and command injection
CVE-2022-41674, CVE-2022-42719, CVE-2022-42720, CVE-2022-42721, CVE-2022-42722Multiple issues in mac80211 and cfg80211
CVE-2022-39173wolfSSL buffer overflow during a TLS 1.3 handshake
CVE-2021-32019XSS via missing input validation of host names displayed
CVE-2021-33425Stored XSS in hostname UCI variable
CVE-2021-28961luci-app-ddns: Multiple authenticated RCEs
CVE-2020-36177wolfSSL heap buffer overflow in RsaPad_PSS
CVE-2021-22161netifd and odhcp6c routing loop on IPv6 point to point links
CVE-2020-25681, CVE-2020-25682, CVE-2020-25683, CVE-2020-25684, CVE-2020-25685, CVE-2020-25686, CVE-2020-25687dnsmasq multiple vulnerabilities
OpenWrt forum break-in on 16-Jan-2021
CVE-2020-25705Linux kernel - ICMP rate limiting can be used to facilitate DNS poisoning attack
CVE-2020-28951libuci import heap use after free
CVE-2020-11750umdns out-of-bounds reads of heap data and possible buffer overflow
CVE-2020-11752relayd out-of-bounds reads of heap data and possible buffer overflow
CVE-2020-8597ppp buffer overflow vulnerability
CVE-2020-7982Opkg susceptible to MITM
CVE-2020-7248libubox tagged binary data JSON serialization vulnerability
CVE-2019-19945uhttpd invalid data access via HTTP POST request
CVE-2019-5101, CVE-2019-5102ustream-ssl information disclosure
LuCI stored XSS
CVE-2019-17367LuCI CSRF vulnerability