CVE Tools

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker NewsBy The Hacker News

Patchodhcpd

Our summary

OpenWrt has issued version 24.10.8 to resolve a severe stack overflow vulnerability in its DHCPv6 implementation, along with several other remotely exploitable flaws in default network services. The primary issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1, allows an unauthenticated attacker to send a specially crafted DHCPv6 REQUEST packet to UDP port 547, potentially leading to arbitrary code execution as root. This is particularly concerning because embedded systems often lack protections like ASLR or stack canaries. The update also addresses multiple pre-authentication issues in odhcpd, including out-of-bounds writes and denial-of-service conditions. Users are advised to upgrade to either 24.10.8 or 25.12.5 immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store