[CRITICAL] "Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root"
criticalDetails
A critical stack overflow vulnerability in the OpenWrt DHCPv6 server (odhcpd) allows an unauthenticated, remote attacker to execute arbitrary code as root. The flaw is triggered by a specifically crafted DHCPv6 request, enabling an attacker to overwrite a stack buffer.
Affected Systems
All OpenWrt versions prior to 24.10.8.
Potential Impact
Complete takeover of affected network devices, including routers and access points. This could lead to network traffic interception, lateral movement into the internal network, and deployment of persistent malware.
Mitigations
Immediately upgrade all OpenWrt instances to version 24.10.8 or later. Monitor network logs for unusual DHCPv6 traffic.