HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

LuCI DHCPv6 Lease Hostname Stored XSS (CVE‑2026‑61876) Enables Remote Code Execution on OpenWrt Routers

A stored XSS vulnerability (CVE‑2026‑61876) in OpenWrt’s LuCI interface allows an unauthenticated LAN attacker to inject JavaScript via DHCPv6 client FQDN. The issue illustrates a control‑validation gap that SOC 2 audit programs must monitor and document.

LiveThreat™ Intelligence · 📅 August 12, 2026· 📰 exploit-db.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
2 recommended
📰
Source
exploit-db.com

LuCI DHCPv6 Lease Hostname Stored XSS (CVE‑2026‑61876) Enables Remote Code Execution on OpenWrt Routers

What Happened — A stored cross‑site scripting (XSS) vulnerability (CVE‑2026‑61876) was disclosed in OpenWrt’s LuCI web interface. An unauthenticated attacker on the same LAN can inject malicious JavaScript via the DHCPv6 client FQDN option, which is later rendered unsanitized in the status tables, potentially allowing execution of arbitrary code in the administrator’s browser session.

Why It Matters for Compliance & Audit Readiness

  • The flaw highlights a missing input‑validation control, a gap that SOC 2’s CC6.1 (System Operations) and CC7.1 (Change Management) require organizations to monitor continuously.
  • It underscores the importance of maintaining auditable evidence that third‑party open‑source components are patched—a core use case for Verisq’s Control‑Mapping capability.
  • Demonstrates why continuous‑compliance programs must capture remediation tickets and patch‑level evidence to provide a defensible audit trail.

Who Is Affected — Vendors and enterprises that deploy OpenWrt‑based routers, ISPs, managed‑service providers, and any organization exposing the LuCI UI to internal users.

Recommended Actions

  • Upgrade LuCI to a version that includes commit 55379d0 (or later) which fixes the XSS issue.
  • Map the input‑validation control to SOC 2 CC6.1, capture the patch‑deployment ticket as evidence, and feed it into your continuous‑compliance dashboard.
  • Deploy automated static‑code scanning for XSS patterns in web UI components and integrate findings with your control‑evidence pipeline. Source: https://www.exploit-db.com/exploits/52637

Technical Notes — The attack vector is DHCPv6 option 39 (Client FQDN); the malicious hostname is stored by odhcpd and rendered via innerHTML without sanitization. CVSS 8.8 (High). Source: https://www.exploit-db.com/exploits/52637

📰 Original Source
https://www.exploit-db.com/exploits/52637

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →