CVE-2026-61876: LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61876?
The severity of CVE-2026-61876 is rated high with a score of 8.8.
How does CVE-2026-61876 affect LuCI?
CVE-2026-61876 affects LuCI by allowing attackers to perform stored cross-site scripting via DHCPv6 lease hostnames.
Who is vulnerable to CVE-2026-61876?
Administrators of LuCI systems are vulnerable to CVE-2026-61876 if they view DHCP lease pages.
How do I fix CVE-2026-61876?
To fix CVE-2026-61876, update LuCI to the latest version that addresses the encoding issue with DHCPv6 lease hostnames.
What can attackers do with CVE-2026-61876?
Attackers can exploit CVE-2026-61876 to inject HTML markup that executes in the administrator's browser.