A crafted WiFi SSID can trigger an XSS vulnerability in OpenWRT's LuCI web interface when an administrator opens the wireless scan page. The vulnerability exists in wireless.js within luci-mod-network, where SSID values are passed unsanitized into innerHTML. Using two access points simultaneously to overcome the 32-byte SSID

6m read timeFrom mxsasha.eu
Post cover image
Table of contents
The XSS vulnerabilityOvercoming length limits with two SSIDsEscalation to rootFixDownstreamDisclosure timelineOther vendorsA broader patternReferences

Sort: