The point: CVE-2026-53921 (CVSS 9.8) allows unauthenticated attackers to trigger stack buffer overflow in the odhcpd daemon via malicious DHCPv6 packets, enabling root code execution.
OpenWrt has released version 24.10.8 to address a critical stack overflow vulnerability in the DHCPv6 stack. The flaw allows unauthenticated attackers within network range to achieve remote code execution with root privileges.
The vulnerability CVE-2026-53921, with a CVSS score of 9.8, affects OpenWrt’s DHCPv6 stack. An attacker who can reach the network can overflow a stack buffer in the odhcpd daemon via a specially crafted DHCPv6 packet. Since DHCPv6 services are enabled by default in OpenWrt, the attack surface is considerable.
The vulnerability enables code execution with root privileges, potentially allowing an attacker to gain full control over affected routers. This is particularly critical for OpenWrt instances deployed in enterprise environments and ISP infrastructure, where DHCPv6 is required for IPv6 address assignment.
The fix is included in version 24.10.8 and later. Administrators should deploy these patches immediately, especially for devices that are externally accessible or operated in critical network segments. The update also addresses additional remotely triggerable flaws in other network services that are enabled by default.
Source: thehackernews.com · Published 28 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.