OpenWrt Releases Address Critical Security Vulnerabilities
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
OpenWrt has released updates for versions 24.10.8 and 25.12.5 to address multiple security vulnerabilities, including critical issues in the DHCP server odhcpd. These vulnerabilities can be exploited remotely without authentication, posing significant risks to users. The most severe vulnerability (CVE-2026-53921) allows attackers to execute code via a buffer overflow with a single UDP packet. Another vulnerability (CVE-2026-62948) enables Stored Cross-Site Scripting through manipulated FQDN hostnames. OpenWrt's LuCI web interface also received patches for high-risk vulnerabilities. Users are strongly advised to update their firmware to minimize exposure to potential attacks. The 24-series is now in security maintenance mode, receiving only critical updates. The updates include security patches for components like OpenSSL and dnsmasq, which also address various vulnerabilities.
Key Points: • OpenWrt updates fix critical vulnerabilities in DHCP and LuCI web interface. • CVE-2026-53921 allows remote code execution via a buffer overflow. • Users are urged to upgrade to the latest firmware to mitigate risks.