CVE-2020-28951: Openwrt

Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.

libuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_parse_package in file.c and uci_strdup in util.c.

Affected products

  • Openwrt Openwrt: before 18.06.9 (fixed in 18.06.9); from 19.07.0, before 19.07.5 (fixed in 19.07.5)

Published 2020-11-19. Last modified 2026-06-17.