OpenWrt Releases Critical Security Updates for DHCPv6 Vulnerabilities

OpenWrt Releases Critical Security Updates for DHCPv6 Vulnerabilities

First seen 29 Jul 2026, 12:14 UTC Heise.DeScworldgithub.com 80% similarity 72.0

Article Content

Browse articles
ThreatCluster

OpenWrt has released updates for versions 24.10.8 and 25.12.5 to address critical security vulnerabilities. The most severe issue is a buffer overflow in the odhcpd DHCP server, allowing unauthenticated attackers to execute code remotely (CVE-2026-53921, CVSS 9.8). Another vulnerability allows for stored XSS through manipulated FQDN hostnames (CVE-2026-62948, CVSS 9.6). Other fixes include vulnerabilities in the LuCI web interface and SSH service. Users are strongly advised to update their firmware to mitigate these risks, as many of the affected services are enabled by default. The updates also include patches for OpenSSL, dnsmasq, and the Linux kernel, which address various security issues. OpenWrt's 24.10 series is in security maintenance with an end-of-life date set for September 2026.

Key Points: • Critical vulnerabilities in OpenWrt's DHCP server allow remote code execution. • Users are urged to update to the latest firmware versions to minimize risks. • The updates address multiple security flaws, including stored XSS and SSH vulnerabilities.

ThreatCluster AI How this analysis works

Timeline

2026-07-15
CVE-2026-62948 published
A stored XSS vulnerability in the LuCI web interface was disclosed, affecting OpenWrt users.
Heise.De
2026-07-28
Public exploit for CVE-2026-53921 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-07-29
OpenWrt releases security updates
OpenWrt versions 24.10.8 and 25.12.5 released to fix critical vulnerabilities, including a buffer overflow in odhcpd.
Scworld
2026-07-29
Developers recommend firmware updates
OpenWrt developers urge users to apply updates promptly to mitigate risks from newly discovered vulnerabilities.
Heise.De

Community

Browse all →

Tracked Entities in This Story