Skip to main content
Security

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root Image: Primary
OpenWrt released version 24.10.8 on Monday to fix a critical DHCPv6 stack overflow and other remotely triggerable flaws in network services enabled by default, the project said. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1, allows an unauthenticated attacker to overwrite a stack buffer in the odhcpd daemon through a crafted DHCPv6 REQUEST sent to UDP port 547. The advisory notes that odhcpd runs as root and that embedded hardware commonly lacks stack canaries and address space layout randomization, making code execution a realistic outcome on typical devices. Public Python proof-of-concept code for both documented overflow paths is included in the advisory. Users on the 24.10 branch should install 24.10.8, while users on 25.12 should install 25.12.5. As of July 28, OpenWrt materials did not report exploitation in the wild, and the flaw was absent from CISA's Known Exploited Vulnerabilities catalog version 2026.07.27. The release also addresses other pre-authentication weaknesses in odhcpd, three HTTP request-smuggling bugs in uhttpd, and a DHCPv6 hostname-injection flaw tracked as CVE-2026-62948. Separately, an AI-assisted audit by Hacker House identified command-injection, path-traversal, and cross-site scripting weaknesses in optional LuCI components. OpenWrt maintainer Hauke Mehrtens published a pull request on July 26 crediting Hacker House, but it remained open and unmerged as of July 28. Those fixes were not part of OpenWrt 24.10.8.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...

Products Security
Products Security

Figma launches Japan data residency for enterprise file hosting

Figma introduced data residency in Japan, letting enterprise customers store Figma Design, FigJam, Figma Slides, and Figma Make file data in the country. The company said the option responds to customer demand for domestic storag...