hacker-news · Crawled Jul 28, 2026

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

2 CVEs
Read original article ↗

AI Summary

OpenWrt released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, which allows unauthenticated attackers to execute code as root on affected devices. The flaw resides in the odhcpd service and can be triggered by sending a crafted DHCPv6 REQUEST to UDP port 547. Additional vulnerabilities in LuCI components, including command injection, path traversal, and stored XSS, were identified by Hacker House through an AI-assisted audit, though exploitation in the wild has not been reported.

AI-extracted · verify before operational use

Extracted Entities 2 found

MITRE ATT&CK TTPs 6 techniques