luci-app-upnp contains a stored cross-site scripting vulnerability that allows unauthenticated LAN clients to inject JavaScript via UPnP IGD AddPortMapping SOAP requests. Attackers can send malicious HTML in the NewPortMappingDescription field, which miniupnpd stores and luci-app-upnp renders without output encoding, executing the payload when administrators view the UPnP or Status pages.
References
Configurations
No configuration.
History
13 Jul 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/openwrt/luci/security/advisories/GHSA-8v49-6387-7f89 - |
12 Jul 2026, 12:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-12 12:16
Updated : 2026-07-13 19:28
NVD link : CVE-2026-61875
Mitre link : CVE-2026-61875
CVE.ORG link : CVE-2026-61875
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
