#6
The Hacker News
general
July 28, 2026 at 12:56 UTC
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
By [email protected] (The Hacker News)
AI Summary
OpenWrt released version 24.10.8 to patch CVE-2026-53921 (CVSS 9.8), a critical stack buffer overflow in the DHCPv6 server daemon odhcpd that allows unauthenticated remote code execution as root on affected routers. The flaw is triggered via a crafted DHCPv6 packet against the default configuration, meaning no special setup is required for exploitation. Administrators running OpenWrt on network edge devices should upgrade immediately given the network-accessible attack surface.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →