Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.
| Software | From | Fixed in |
|---|---|---|
| openwrt / openwrt | 22.03.0-rc6 | 22.03.0-rc6.x |
| openwrt / openwrt | - | 21.02.3 |