Cross-site scripting in OpenWrt - CVE-2026-32721
Published: April 28, 2026
OpenWrt
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script in the user's browser.
The vulnerability exists due to cross-site scripting in the wireless scan results rendering function in wireless.js when rendering SSID values from scan results in the joining wireless client scan modal. A remote attacker can broadcast a specially crafted SSID to execute arbitrary script in the user's browser.
User interaction is required to open the scan modal.