Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
OpenWrt has released version 24.10.8 to address a critical vulnerability (CVE-2026-53921) in its DHCPv6 stack, allowing unauthenticated attackers to execute code as root on devices running the firmware. The vulnerability stems from a stack overflow caused by crafted DHCPv6 REQUESTs, and is exacerbated by the lack of stack canaries and ASLR in many embedded devices. The advisory highlights several other security fixes related to LuCI components, including command injection, path traversal, and stored XSS, all of which were identified through an AI-assisted audit by Hacker House. While exploitation has not been reported, the vulnerability poses a significant risk due to its ease of exploitation and potential for complete device compromise.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
