OpenWrt Releases Address Critical Security Vulnerabilities

OpenWrt Releases Address Critical Security Vulnerabilities

First seen 29 Jul 2026, 12:14 UTC Heise.Degithub.com 80% similarity 72.6

Article Content

Browse articles
ThreatCluster

OpenWrt has released updates for versions 24.10.8 and 25.12.5 to address multiple security vulnerabilities, including critical issues in the DHCP server odhcpd. These vulnerabilities can be exploited remotely without authentication, posing significant risks to users. The most severe vulnerability (CVE-2026-53921) allows attackers to execute code via a buffer overflow with a single UDP packet. Another vulnerability (CVE-2026-62948) enables Stored Cross-Site Scripting through manipulated FQDN hostnames. OpenWrt's LuCI web interface also received patches for high-risk vulnerabilities. Users are strongly advised to update their firmware to minimize exposure to potential attacks. The 24-series is now in security maintenance mode, receiving only critical updates. The updates include security patches for components like OpenSSL and dnsmasq, which also address various vulnerabilities.

Key Points: • OpenWrt updates fix critical vulnerabilities in DHCP and LuCI web interface. • CVE-2026-53921 allows remote code execution via a buffer overflow. • Users are urged to upgrade to the latest firmware to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-07-15
CVE-2026-62948 published
A Stored Cross-Site Scripting vulnerability in LuCI was disclosed, affecting OpenWrt users.
Heise.De
2026-07-28
Public exploit for CVE-2026-53921 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-07-29
OpenWrt releases security updates
OpenWrt 24.10.8 and 25.12.5 released to address critical vulnerabilities, including buffer overflow and XSS issues.
Heise.De

Community

Browse all →

Tracked Entities in This Story