CVE Tools
Back to feed
Patch released odhcpd rce OpenWrt network-edge

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker News·By The Hacker News··8 min read
CVE Tools coverage

OpenWrt has issued version 24.10.8 to resolve a severe stack overflow vulnerability in its DHCPv6 implementation, along with several other remotely exploitable flaws in default network services. The primary issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1, allows an unauthenticated attacker to send a specially crafted DHCPv6 REQUEST packet to UDP port 547, potentially leading to arbitrary code execution as root. This is particularly concerning because embedded systems often lack protections like ASLR or stack canaries. The update also addresses multiple pre-authentication issues in odhcpd, including out-of-bounds writes and denial-of-service conditions. Users are advised to upgrade to either 24.10.8 or 25.12.5 immediately.