Impact
The vulnerability arises because the LuCI interface does not encode DHCPv6 lease hostnames before rendering them in status tables. An attacker on a nearby network can send a DHCPv6 packet with a client FQDN that contains script tags or other HTML markup. When an administrator views the DHCP lease page, the malicious content is rendered and the embedded script runs in the admin’s browser, allowing the attacker to execute arbitrary client‑side code with the privileges of the browser session.
Affected Systems
The issue affects the OpenWrt LuCI web interface, specifically the modules that display DHCPv6 lease information. No specific version numbers are listed in the advisory, so any OpenWrt release that includes the affected LuCI code is considered vulnerable.
Risk and Exploitability
With a CVSS score of 9.4 the vulnerability is considered critical. The EPSS score is <1%, indicating a low probability of exploitation, but the lack of a KEV listing does not reduce the likelihood of exploitation; adjacent network attackers can exploit it by simply broadcasting a crafted DHCPv6 message over the local network, which most router configurations allow by default.
OpenCVE Enrichment