CVE-2026-62948 is a DHCPv6 hostname-injection flaw in OpenWrt that can produce stored cross-site scripting (XSS) when an administrator opens the LuCI leases page. It is addressed in OpenWrt 24.10.8 and 25.12.5.
CVE-2026-62948 is a DHCPv6 hostname-injection flaw in OpenWrt that can produce stored cross-site scripting (XSS) when an administrator opens the LuCI leases page. It is addressed in OpenWrt 24.10.8 and 25.12.5.