CVE-2019-18992: Openwrt

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

OpenWrt 18.06.4 allows XSS via these Name fields to the cgi-bin/luci/admin/network/firewall/rules URI: "Open ports on router" and "New forward rule" and "New Source NAT" (this can occur, for example, on a TP-Link Archer C7 device).

Affected products

  • Openwrt Openwrt: version 18.06.4 only

Published 2019-12-03. Last modified 2026-06-17.