🔴 Critical | Source: The Hacker News
A critical vulnerability (CVE-2026-53921, CVSS 9.8) in OpenWrt’s DHCPv6 daemon odhcpd allows an unauthenticated attacker with network access to trigger a stack buffer overflow and execute arbitrary code as root. The flaw is present in a service enabled by default, significantly widening the attack surface. OpenWrt 24.10.8 has been released to address this and a number of related remotely exploitable flaws in default network services.
Security Architect’s Take: Audit any OpenWrt-based devices in your environment — including edge routers, SD-WAN appliances, or lab infrastructure — and update to 24.10.8 immediately. Where DHCPv6 is not required, disable odhcpd or restrict access to the service at the network perimeter to reduce exposure until patching is complete.
Original advisory: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root