A vulnerability in OpenWrt's luci-app-banip can let an unauthenticated remote attacker evade blocking by manipulating how the application extracts IP addresses from log entries. According to VulnCheck, the flaw is in an awk-based parser that selects the first IPv4 address found in a log line without verifying that the address appears in the correct field, allowing an attacker to place a different IP address in a controllable value such as a username and cause banIP to block the wrong host.
A related OpenWrt LuCI commit updated luci-app-banip help text for the ban_logterm option to clarify that log parsing uses the last IP address on each line by default and that users can prefix a term with first: for source-first log formats such as nginx. The change indicates maintainers adjusted guidance around IP extraction behavior, highlighting the risk that incorrect log-field selection can leave the real attacker unblocked while disrupting legitimate systems through misdirected bans.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
VulnCheck published an advisory describing a log parsing flaw in luci-app-banip in which an awk-based parser extracts the first IPv4 address from a log line without validating its position. The issue could let an unauthenticated remote attacker inject an arbitrary IP address into a controllable field, causing banIP to block the wrong target while the real attacker remains unblocked.
A code change in the OpenWrt LuCI repository updated luci-app-banip to version 1.8.10-1 and revised the ban_logterm help text to clarify that parsing uses the last IP address per log line by default, with a 'first:' prefix available for source-first formats such as nginx.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.