Back to the feed

~/article/critical-openwrt-dhcpv6-flaw-could-let-unauthenticated-attackers-run-cod-1hoqoh
highSource: The Hacker News

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Referenced CVEs

Topics

~/cymesh.net

This is what cymesh.net is for

Certificate and hostname problems are the ones you find out about from your users. cymesh.net finds them first.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/critical-openwrt-dhcpv6-flaw-could-let-unauthenticated-attackers-run-cod-1hoqoh