OpenWrt: Updates close partly critical security vulnerabilities

The open-source router firmware OpenWrt has been launched in new variations that close a number of security vulnerabilities. Some of those may be exploited from the community and are partly in providers which are activated by default, the OpenWrt builders clarify.
According to the release announcement, the release OpenWrt 24.10.8 from the weekend is affected, however OpenWrt 25.12.5 from the start of the month additionally brings the software program patches. The 24-series improvement department now solely receives security updates and no new options, however an entire sequence of security fixes. The most severe is a vulnerability within the DHCP server odhcpd, which is lively by default. A buffer overflow on the stack can happen when processing DHCPv6 IA responses.
With a single UDP packet, attackers from the community can exploit the buffer overflow with out prior authentication. As the builders specify within the vulnerability report, the customarily lacking Address Space Layout Randomization (ASLR) on embedded platforms makes the execution of injected code extra probably (CVE-2026-53921, CVSS 9.8, Risk “critical”). Another odhcpd vulnerability permits DHCPv6 purchasers with out prior authentication to smuggle traces into the lease recordsdata with manipulated FQDN hostnames, resulting in a Stored Cross-Site Scripting vulnerability in the LuCI DHCPv6 Leases status page (CVE-2026-62948, CVSS 9.6, Risk “critical”).
Several fixes have an effect on OpenWrt’s LuCI net interface, closing, amongst different issues, additional Stored Cross-Site Scripting vulnerabilities, that are categorised as “high” danger. Also noteworthy is a security patch for dropbear-SSH, which fixes a vulnerability from 2019. Updated parts resembling OpenSSL 3.0.21, dnsmasq 2.93, or the Linux kernel 6.6.144 additionally close a number of security vulnerabilities.
Update Firmware
Anyone utilizing OpenWrt ought to deploy the up to date firmware builds to the units of their networks. This minimizes the assault floor for malicious actors. Since OpenWrt is commonly accessible from the web as a router working system, customers ought to apply the updates promptly.
In March, the OpenWrt 25.12.0 version branch introduced a change in the package manager. The model additionally helps extra units.
(dmk)
Source link

