Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
Overview
OpenWrt has released version 24.10.8 to address a serious vulnerability in its DHCPv6 service, identified as CVE-2026-53921. This flaw has a CVSS score of 9.8, indicating a high level of risk, as it allows unauthenticated attackers to exploit a stack overflow in the odhcpd component. If attackers can reach the DHCPv6 server, they could potentially execute code with root privileges. This vulnerability affects users running OpenWrt versions that include the vulnerable DHCPv6 stack, which is enabled by default in many configurations. Users are strongly advised to update their systems to maintain security and prevent unauthorized access.
Key Takeaways
- Affected Systems: OpenWrt versions with the vulnerable DHCPv6 stack, specifically those using odhcpd.
- Action Required: Users should update to OpenWrt version 24.
- Timeline: Newly disclosed
Original Article Summary
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6
Impact
OpenWrt versions with the vulnerable DHCPv6 stack, specifically those using odhcpd.
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users should update to OpenWrt version 24.10.8 or later to mitigate this vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 2 more.