CVE-2026-61876 – LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting

​CVE ID :CVE-2026-61876

Published : July 12, 2026, 12:16 p.m. | 6 hours, 29 minutes ago

Description :LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator’s browser when viewing DHCP lease pages.

Severity: 9.4 | CRITICAL

Visit the link for more details, such as CVSS details, affected products, timeline, and more… To Read More Visit Read More