PT-2021-7936 · Openwrt · Openwrt Luci

Published

2021-05-25

·

Updated

2023-05-24

·

CVE-2021-33425

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions OpenWrt LuCI version 19.07
Description The issue is related to a stored cross-site scripting (XSS) vulnerability in the web interface of OpenWrt LuCI. This vulnerability allows attackers to inject arbitrary Javascript code into the OpenWrt Hostname via the Hostname Change operation, potentially enabling remote attackers to perform cross-site scripting attacks.
Recommendations For OpenWrt LuCI version 19.07, consider disabling the Hostname Change operation until a patch is available to prevent exploitation of the stored XSS vulnerability. Restrict access to the web interface to minimize the risk of exploitation. Avoid using the Hostname Change operation in the affected web interface until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-05701
CVE-2021-33425

Affected Products

Openwrt Luci