CyberRota Analysis
AI-GeneratedLuCI versions are vulnerable due to improper encoding of DHCPv6 lease hostnames, enabling adjacent network attackers to inject malicious HTML markup. This flaw allows attackers to execute scripts in the administrator's browser when they view DHCP lease pages, potentially leading to unauthorized actions or data exposure. Network administrators and organizations using LuCI should prioritize patching this vulnerability to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.