Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

rustypup

Expert Member
Joined
Jan 28, 2016
Messages
4,281
Reaction score
4,586

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.

The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6 REQUEST.
 
Once again the beauty of opensource.... more people able to find the problems and more people able to help fix it.
 
Top
Sign up to the MyBroadband newsletter
X