


Perceptive Security
SOC/SIEM Consultancy

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTM…
Published:
1 August 2026 at 00:00:00
Alert date:
1 August 2026 at 16:10:40
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies, Mobile & IoT
CVE-2026-67352 is a stored cross-site scripting (XSS) vulnerability in luci-app-https-dns-proxy, a component of the OpenWrt LuCI web interface. The vulnerability exists in the resolver_url parameter, which is rendered as raw HTML without proper sanitization. Authenticated users can inject malicious JavaScript through this parameter, which executes in the administrator's browser when they view the HTTPS DNS Proxy status page. This represents a privilege escalation risk as a lower-privileged authenticated user could potentially compromise an administrator's session. The attack is persistent (stored XSS) making it more dangerous than reflected XSS variants. Exploitation requires the attacker to be authenticated to the device. The vulnerability was disclosed via GitHub Security Advisories and VulnCheck.
Technical details
Mitigation steps:
Affected products:
luci-app-https-dns-proxy
OpenWrt LuCI
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-67352
https://github.com/openwrt/luci/security/advisories/GHSA-c6vf-395q-4jv6
https://www.vulncheck.com/advisories/luci-app-https-dns-proxy-stored-xss-via-resolver-url
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
