Description
luci-app-banip contains a log parsing vulnerability where the awk-based parser extracts the first IPv4 address from log lines regardless of field position, allowing attackers to inject arbitrary IPs via attacker-controlled fields like usernames. An unauthenticated remote attacker can inject an IP address into the login username field, causing banIP to block the wrong target while the real attacker remains unblocked.
CVSS breakdown
CVSS 4.0
Attack Vector
Network
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Confidentiality (Vulnerable System)
None
Integrity (Vulnerable System)
None
Availability (Vulnerable System)
High
Confidentiality (Subsequent System)
None
Integrity (Subsequent System)
None
Availability (Subsequent System)
None
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- openwrt / luci0 – 0.11.1
- openwrt / lucid9bbc372e29618a8807b693a1ccf6d0e42cd196c – d9bbc372e29618a8807b693a1ccf6d0e42cd196c
- openwrt / luci-app-banip0 – 0.11.1
- openwrt / luci-app-banipd9bbc372e29618a8807b693a1ccf6d0e42cd196c – d9bbc372e29618a8807b693a1ccf6d0e42cd196c
Updated 2m ago · 8 sources