< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-28T18:26:14+05:30

Critical OpenWrt DHCPv6 Stack Overflow Vulnerability Allows Root Code Execution

A critical stack overflow vulnerability (CVE-2026-53921) in OpenWrt's DHCPv6 implementation allows unauthenticated attackers to execute arbitrary code as root by exploiting crafted DHCPv6 REQUEST messages. The vulnerability was addressed in OpenWrt 24.10.8 and 25.12.5, with additional security issues in LuCI components still under review.

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.

The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

Read original article

*** END OF TRANSMISSION ***