В OpenWrt исправили критическую уязвимость в DHCPv6-сервере
Developers of OpenWrt have issued updates to resolve a critical vulnerability in its DHCPv6 server that could allow unauthenticated attackers to execute arbitrary code with root privileges, potentially leading to full device compromise. The flaw, assigned CVE-2026-53921 and rated 9.8 on the CVSS scale, stems from a buffer overflow in the odhcpd component handling DHCPv6 requests. An attacker could exploit this by sending a specially crafted DHCPv6 REQUEST packet to UDP port 547. Because many routers lack protections like ASLR and stack guards, a successful attack would be feasible. Patches were included in OpenWrt versions 24.10.8 and 25.12.5, with users advised to upgrade immediately. Additional bugs affecting network services, including memory leaks and denial-of-service issues, were also addressed.