CVE-2026-62184

luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the login username field, causing banIP to block the wrong target while the real attacker remains unblocked.
Configurations

No configuration.

History

15 Jul 2026, 19:18

Type Values Removed Values Added
References () https://github.com/openwrt/luci/security/advisories/GHSA-r6hx-4f83-vp8m - () https://github.com/openwrt/luci/security/advisories/GHSA-r6hx-4f83-vp8m -

13 Jul 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-13 22:16

Updated : 2026-07-15 21:02


NVD link : CVE-2026-62184

Mitre link : CVE-2026-62184

CVE.ORG link : CVE-2026-62184


JSON object : View

Products Affected

No product.

CWE
CWE-116

Improper Encoding or Escaping of Output