Critical OpenWrt DHCPv6 Flaw CVE-2026-53921 Allows Unauthenticated Remote Code Execution as Root
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…
OpenWrt has released versions 24.10.8 and 25.12.5 to patch a critical DHCPv6 stack overflow vulnerability, CVE-2026-53921, rated 9.8 on CVSS 3.1. The…
CVE-2026-53921 is a critical stack overflow vulnerability in OpenWrt's odhcpd DHCPv6 server, rated 9.8 CVSS 3.1. An unauthenticated attacker can send a…
CVE-2026-62948 is a DHCPv6 hostname-injection flaw in OpenWrt that can produce stored cross-site scripting (XSS) when an administrator opens the LuCI leases…
CVE-2026-62947 is a path traversal vulnerability in OpenWrt's cgi-io component that can expose arbitrary root-readable files. It requires an authenticated session with…
OpenWrt is an open-source operating system for embedded devices, commonly used in routers. It provides a fully writable filesystem with package management.…
Hacker House is a cybersecurity firm co-founded by Matthew Hickey (Hacker Fantastic). It conducted an AI-assisted audit of OpenWrt's LuCI and uhttpd…
odhcpd is the DHCP and DHCPv6 server daemon used in OpenWrt. It runs as root and is affected by CVE-2026-53921, a critical…
LuCI is the default web-based user interface for OpenWrt. An AI-assisted audit by Hacker House identified multiple vulnerabilities in LuCI components, including…
uhttpd is the HTTP server used in OpenWrt. It was found to have three HTTP request-smuggling bugs, which were fixed in OpenWrt…
cgi-io is a CGI component in OpenWrt for file I/O operations. It is affected by CVE-2026-62947, a path traversal vulnerability that can…