Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-62947
CVE
CVE-2026-62947
View on NVD ↗
OpenWrt: ACL bypass and arbitrary root file read via cgi-io cgi-download
MITRE ATT&CK TTPs
6
T1059.001
PowerShell
Execution
T1078
Valid Accounts
Defense Evasion
T1134
Access Token Manipulation
Defense Evasion
T1211
Exploitation for Defense Evasion
Defense Evasion
T1552.001
Credentials In Files
Credential Access
T1620
Reflective Code Loading
Defense Evasion
Source Articles
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, which allows unauthenticated attackers to execute code as root on affected devices. The flaw resides in the odhcpd service and can be triggered by sending a crafted DHCPv6 REQUEST to UDP port 547. Additional vulnerabilities in LuCI components, including command injection, path traversal, and stored XSS, were identified by Hacker House through an AI-assisted audit, though exploitation in the wild has not been reported.
hacker-news
Jul 28, 2026