Skip to main content
Back to Newswire
Security

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root Image: Primary
OpenWrt released version 24.10.8 on Monday to fix a critical DHCPv6 stack overflow and other remotely triggerable flaws in network services enabled by default, the project said. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1, allows an unauthenticated attacker to overwrite a stack buffer in the odhcpd daemon through a crafted DHCPv6 REQUEST sent to UDP port 547. The advisory notes that odhcpd runs as root and that embedded hardware commonly lacks stack canaries and address space layout randomization, making code execution a realistic outcome on typical devices. Public Python proof-of-concept code for both documented overflow paths is included in the advisory. Users on the 24.10 branch should install 24.10.8, while users on 25.12 should install 25.12.5. As of July 28, OpenWrt materials did not report exploitation in the wild, and the flaw was absent from CISA's Known Exploited Vulnerabilities catalog version 2026.07.27. The release also addresses other pre-authentication weaknesses in odhcpd, three HTTP request-smuggling bugs in uhttpd, and a DHCPv6 hostname-injection flaw tracked as CVE-2026-62948. Separately, an AI-assisted audit by Hacker House identified command-injection, path-traversal, and cross-site scripting weaknesses in optional LuCI components. OpenWrt maintainer Hauke Mehrtens published a pull request on July 26 crediting Hacker House, but it remained open and unmerged as of July 28. Those fixes were not part of OpenWrt 24.10.8.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.