


Perceptive Security
SOC/SIEM Consultancy

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
Published:
28 juli 2026 om 12:56:14
Alert date:
28 juli 2026 om 14:01:08
Source:
thehackernews.com
Network Infrastructure, Mobile & IoT, Zero-Day Vulnerabilities
OpenWrt has released version 24.10.8 to address a critical DHCPv6 stack overflow vulnerability tracked as CVE-2026-53921, rated 9.8 on CVSS 3.1. The flaw exists in the odhcpd daemon and allows an unauthenticated attacker who can reach the DHCPv6 server to overwrite a stack buffer via a crafted DHCPv6 packet. Successful exploitation could result in remote code execution with root privileges. The vulnerability affects network services enabled by default on OpenWrt devices. The update also patches a broader set of remotely triggerable flaws in default-enabled network services. OpenWrt is widely used in routers and embedded network devices, making this a high-impact vulnerability for network infrastructure. Users are strongly advised to upgrade to version 24.10.8 immediately.
Technical details
Mitigation steps:
Affected products:
OpenWrt
odhcpd
Related links:
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
