CyberSecurity News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
AI summary
A critical vulnerability in OpenWrt's DHCPv6 stack has been discovered, allowing unauthenticated attackers to potentially run code as root. The issue is caused by a stack overflow in the odhcpd service, which can be triggered remotely through a crafted DHCPv6 request. OpenWrt has released version 24.10.8 to address this flaw, as well as other remotely triggerable vulnerabilities in default-enabled network services. The critical issue has been assigned a CVSS score of 9.8, indicating a high level of severity. The vulnerability can be exploited by an attacker who can reach the DHCPv6 server.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

