rustypup
Expert Member
- Joined
- Jan 28, 2016
- Messages
- 4,092
- Reaction score
- 4,272
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt 24.10.8 fixes CVE-2026-53921, a critical odhcpd stack overflow triggered by crafted DHCPv6 requests that could enable code execution.
thehackernews.com
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.
The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 REQUEST.