CVE-2026-53921 is a critical stack overflow vulnerability in OpenWrt's odhcpd DHCPv6 server, rated 9.8 CVSS 3.1. An unauthenticated attacker can send a crafted DHCPv6 REQUEST to overwrite a stack buffer, potentially achieving remote code execution as root. The flaw affects all odhcpd versions prior to the fix in OpenWrt 24.10.8 and 25.12.5. Public proof-of-concept code exists.