top of page
perceptive_background_267k.jpg

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject active HTM…

Published:

31 juli 2026 om 22:00:00

Alert date:

1 augustus 2026 om 14:10:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies, Mobile & IoT

CVE-2026-67352 is a stored cross-site scripting (XSS) vulnerability in luci-app-https-dns-proxy, a component of the OpenWrt LuCI web interface. The vulnerability exists in the resolver_url parameter, which is rendered as raw HTML without proper sanitization. Authenticated users can inject malicious JavaScript through this parameter, which executes in the administrator's browser when they view the HTTPS DNS Proxy status page. This represents a privilege escalation risk as a lower-privileged authenticated user could potentially compromise an administrator's session. The attack is persistent (stored XSS) making it more dangerous than reflected XSS variants. Exploitation requires the attacker to be authenticated to the device. The vulnerability was disclosed via GitHub Security Advisories and VulnCheck.

Technical details

Mitigation steps:

Affected products:

luci-app-https-dns-proxy
OpenWrt LuCI

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page