[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:critical-openwrt-dhcpv6-flaw-could-let-unauthenticated-attackers-run-code-as-roo-ms5swxgh":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"addd1343-e999-4bb3-a314-0b50f9f03a91","Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root","critical-openwrt-dhcpv6-flaw-could-let-unauthenticated-attackers-run-code-as-roo-ms5swxgh","OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across enterprise and ISP networks.","critical","advisory",[12],"CVE-2026-53921",[14,15,16,17],"OpenWrt","odhcpd","uhttpd","LuCI","Identify all OpenWrt devices in your environment and immediately patch to version 24.10.8 or later. If you cannot patch immediately, isolate devices from untrusted networks or disable DHCPv6 service.",[20],"d0cbd3d3-fee2-410e-baa1-f6c10ea64779",null,[23],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fcritical-openwrt-dhcpv6-flaw-could-let.html","active","2026-07-31T08:06:46.834+00:00","2026-07-29T08:06:52.061146+00:00","2026-07-29T08:10:06.128779+00:00",[29],{"id":20,"title":6,"url":23}]