CVE-2019-12272: Openwrt Luci

Critical severity, CVSS 9.8. EPSS: 7.4% chance of exploitation in the next 30 days.

In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.

Affected products

  • Openwrt Luci: up to and including 0.10.0

Published 2019-05-23. Last modified 2026-06-17.