Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

Summary

OpenWrt has released version 24.10.8 to address critical vulnerabilities in its DHCPv6 service. A flaw, CVE-2026-53921, allows unauthenticated attackers to trigger a stack overflow by sending a crafted DHCPv6 packet, potentially leading to remote code execution with root privileges.

IFF Assessment

FOE

This vulnerability allows unauthenticated attackers to execute code as root, posing a significant threat to network security and device integrity.

Severity

9.8 Critical

The CVSS score of 9.8 indicates a critical vulnerability due to its potential for remote exploitation without authentication, leading to full system compromise via code execution as root.

Defender Context

This critical vulnerability in OpenWrt's DHCPv6 service requires immediate attention for network administrators. Defenders should prioritize patching affected devices and monitoring network traffic for suspicious DHCPv6 requests that could indicate exploitation attempts. The severity highlights the ongoing risks associated with default service configurations and the need for diligent vulnerability management.

Read Full Story →