CVE-2026-32721: LuCI luci-mod-network: Possible XSS attack in WiFi scan on Joining Wireless Client modal

Published Mar 19, 2026
·
Updated

LuCI is the OpenWrt Configuration Interface. Versions prior to both 24.10.5 and 25.12.0, contain a stored XSS vulnerability in the wireless scan modal, where SSID values from scan results are rendered as raw HTML without any sanitization. The wireless.js file in the luci-mod-network package passes SSIDs via a template literal to dom.append(), which processes them through innerHTML, allowing an attacker to craft a malicious SSID containing arbitrary HTML/JavaScript. Exploitation requires the user to actively open the wireless scan modal (e.g., to connect to a Wi-Fi access point or survey nearby channels), and only affects OpenWrt versions newer than 23.05/22.03 up to the patched releases (24.10.6 and 25.12.1). The issue has been fixed in version LuCI 26.072.65753~068150b.

Affected Software

4 affected components
openwrt/luci-mod-network>23.05<24.10.6, >22.03<25.12.1
OpenWrt LuCI<26.072.65753-068150b
OpenWrt OpenWrt<24.10.6
OpenWrt OpenWrt>=25.12.0<25.12.1

Event History

Mar 19, 2026
CVE Published
via MITRE·10:46 PM
Data Sourced
via MITRE·10:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability severity of CVE-2026-32721?

CVE-2026-32721 has a medium severity rating due to the potential for stored XSS attacks.

2

How do I mitigate CVE-2026-32721?

To mitigate CVE-2026-32721, upgrade to versions 24.10.5 or 25.12.0 or later of the OpenWrt LuCI interface.

3

What are the affected versions for CVE-2026-32721?

CVE-2026-32721 affects OpenWrt LuCI versions prior to 24.10.5 and 25.12.0, including 23.05 and 22.03.

4

What kind of attack is CVE-2026-32721 associated with?

CVE-2026-32721 is associated with a stored XSS (Cross-Site Scripting) attack that may allow an attacker to execute malicious scripts.

5

Can CVE-2026-32721 affect my wireless configuration?

Yes, CVE-2026-32721 can potentially affect wireless configurations due to the vulnerability in the WiFi scan modal of the LuCI interface.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203