LuCI versions fail to properly encode DHCPv6 lease...
Critical severity
Unreviewed
Published
Jul 12, 2026
to the GitHub Advisory Database
•
Updated Jul 12, 2026
Description
Published by the National Vulnerability Database
Jul 12, 2026
Published to the GitHub Advisory Database
Jul 12, 2026
Last updated
Jul 12, 2026
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.
References