
A reflected cross-site scripting vulnerability in OpenWRT v18.06.2
A reflected cross-site scripting (XSS) vulnerability was identified in EOL Luci OpenWRT v18.06.2 on /cgi-bin/luci/admin/system/packages endpoint.
http://192.168.56.2/cgi-bin/luci/admin/system/packages,

The root cause of the vulnerability is insufficient input sanitization, which allows threat actor to break out of the string and directly execute JavaScript payload.
Exploitation of this vulnerability could allow the attacker to exfiltrate session tokens (cookies), potentially leading to account takeover.
Luci - OpenWRT 18.06.2, branch (git-19.020.41695-6f6641d) - source code