As cited
Copy frozen at (site build).
vulnerabilities
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability (CVE-2026-53921, CVSS 9.8) that allows unauthenticated attackers to overwrite stack buffers in the odhcpd service. The patch also closes additional remotely triggerable flaws in default-enabled network services.
Why it matters: Organizations running OpenWrt devices with DHCPv6 enabled face risk of remote code execution as root from unauthenticated network-adjacent attackers; immediate patching to version 24.10.8 is required.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability (CVE-2026-53921, CVSS 9.8) that allows unauthenticated attackers to overwrite stack buffers in the odhcpd service. The patch also closes additional remotely triggerable flaws in default-enabled network services.
Why it matters: Organizations running OpenWrt devices with DHCPv6 enabled face risk of remote code execution as root from unauthenticated network-adjacent attackers; immediate patching to version 24.10.8 is required.
- Source published
- First seen by Cybersecurity Tracker