CVE-2018-19630: Openwrt Lede

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.

Affected products

  • Openwrt Lede: up to and including 17.01
  • Openwrt Openwrt: up to and including 18.06.1

Published 2018-11-28. Last modified 2026-06-17.