LuCI is the default web-based user interface for OpenWrt. An AI-assisted audit by Hacker House identified multiple vulnerabilities in LuCI components, including command injection, path traversal, and XSS. Fixes were submitted via pull request #8878 but remained unmerged as of July 28.