Skip to content
OpenWrt: Updates close partly critical security vulnerabilities

OpenWrt: Updates close partly critical security vulnerabilities

Heise.De July 29, 2026

The open-source router firmware OpenWrt has been released in new versions that close several security vulnerabilities. Some of these can be exploited from the network and are partly in services that are activated by default, the OpenWrt developers explain.

According to the release announcement, the release OpenWrt 24.10.8 from the weekend is affected, but OpenWrt 25.12.5 from the beginning of the month also brings the software patches. The 24-series development branch now only receives security updates and no new features, but a whole series of security fixes. The most serious is a vulnerability in the DHCP server odhcpd, which is active by default. A buffer overflow on the stack can occur when processing DHCPv6 IA responses.

With a single UDP packet, attackers from the network can exploit the buffer overflow without prior authentication. As the developers specify in the vulnerability report , the often missing Address Space Layout Randomization (ASLR) on embedded platforms makes the execution of injected code more likely (CVE-2026-53921, CVSS 9.8 , Risk “ critical ”). Another odhcpd vulnerability allows DHCPv6 clients without prior authentication to smuggle lines into the lease files with manipulated FQDN hostnames, leading to a Stored Cross-Site Scripting vulnerability in the LuCI DHCPv6 Leases status page (CVE-2026-62948, CVSS 9.6 , Risk “ critical ”).

Several fixes affect OpenWrt's LuCI web interface, closing, among other things, further Stored Cross-Site Scripting vulnerabilities, which are classified as “ high ” risk. Also noteworthy is a security patch for dropbear-SSH, which fixes a vulnerability from 2019. Updated components such as OpenSSL 3.0.21, dnsmasq 2.93, or the Linux kernel 6.6.144 also close several security vulnerabilities.

Anyone using OpenWrt should deploy the updated firmware builds to the devices in their networks. This minimizes the attack surface for malicious actors. Since OpenWrt is often accessible from the internet as a router operating system, users should apply the updates promptly.

In March, the OpenWrt 25.12.0 version branch introduced a change in the package manager . The version also supports more devices.

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities