CVE-2026-61876: Openwrt Luci

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.

Affected products

Published 2026-07-12. Last modified 2026-07-14.