Security Advisory

CVE-2026-61876

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-12 12:07:55
Last updated 2026-07-14 22:03:45
Assigner VulnCheck
CVSS score 9.4
State PUBLISHED

Description

LuCI versions fail to properly encode DHCPv6 lease hostnames before rendering in status tables, allowing adjacent network attackers to inject HTML markup. Attackers can send a DHCPv6 Client FQDN containing script tags that execute in the administrator's browser when viewing DHCP lease pages.