By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Critical OpenWrt DHCPv6 Flaw Allows Root Code Execution

OpenWrt has released version 24.10.8 to address a critical vulnerability within its DHCPv6 implementation, alongside a broader set of remotely exploitable flaws affecting default network services. The most severe of these issues, identified as CVE-2026-53921, carries a critical CVSS 3.1 score of 9.8, as detailed in an advisory on OpenWrt's GitHub repository. This vulnerability permits an unauthenticated attacker, who can reach the DHCPv6 server, to execute arbitrary code with root privileges. The attack vector involves overwriting a stack buffer in the `odhcpd` service by sending a specially crafted DHCPv6 message.
The `odhcpd` service is a daemon responsible for handling DHCPv6 client and server functionalities on OpenWrt devices. By exploiting a stack overflow condition within this service, an attacker can manipulate the program's execution flow. This is achieved by sending a malformed DHCPv6 packet that exceeds the expected buffer size, leading to the overwriting of critical data on the program's call stack. Successful exploitation allows an attacker to inject and run their own malicious code, effectively gaining complete control over the affected router.
Beyond the critical DHCPv6 flaw, OpenWrt's latest release, version 24.10.8, also patches other remotely triggerable vulnerabilities. These issues, while not as severe as CVE-2026-53921, could still pose significant security risks if left unaddressed. The update aims to bolster the overall security posture of OpenWrt-powered devices, which are commonly used in home and small business networking environments. The proactive patching of these vulnerabilities is crucial for maintaining the integrity and security of the network infrastructure managed by OpenWrt.
OpenWrt is a popular open-source Linux distribution primarily used for embedded devices, most notably routers. Its flexibility and customizability have made it a favored choice for network enthusiasts and device manufacturers seeking to deploy advanced networking features. The project's commitment to security is underscored by its rapid response to identified vulnerabilities, ensuring that its user base remains protected against emerging threats. The release of version 24.10.8 signifies a critical security update that all users of affected OpenWrt versions are strongly advised to apply promptly to mitigate the risks associated with these newly disclosed flaws.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.