OpenWrt released 24.10.8 and corresponding 25.12.5 updates to fix a critical remote code execution flaw in odhcpd, tracked as CVE-2026-53921, that could let an unauthenticated attacker send a crafted DHCPv6 REQUEST to UDP port 547 and potentially execute code as root on affected routers. The project said the service release addresses numerous security issues, including several remotely triggerable flaws in default-enabled network services, and strongly recommended that users upgrade. OpenWrt also updated its 24.10 stable release pages to identify 24.10.8 as the latest release in the series.
Beyond the DHCPv6 bug, the release includes fixes across the Linux kernel, dnsmasq, uhttpd, rpcd, cgi-io, LuCI components, umdns, ead, hostapd/wpa_supplicant, dropbear, musl libc, and OpenSSL. Reported issues addressed include three HTTP request-smuggling bugs in uhttpd, a DHCPv6 hostname-injection flaw leading to stored XSS in LuCI, and a path traversal issue in cgi-io tracked as CVE-2026-62947; OpenWrt noted that optional package fixes require separate package updates. The project also said the 24.10 branch is now in security-maintenance mode with end of life projected for September 2026, and advised users to migrate to OpenWrt 25.12 before then.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
A report said OpenWrt 24.10.8 and corresponding 25.12.5 updates fixed CVE-2026-53921, a critical odhcpd DHCPv6 stack overflow that could allow unauthenticated remote code execution as root. It also highlighted other fixes in odhcpd, uhttpd, LuCI, and cgi-io, while noting some additional LuCI fixes were still under review.
An article described CVE-2026-31431, nicknamed "Copy Fail," as a critical Linux kernel local privilege-escalation vulnerability in the algif_aead module that could let an unprivileged user gain root without persistent disk changes. The write-up also warned of possible container-to-host compromise and recommended patching or disabling the module if unused.
A revision to the OpenWrt 24.10.8 release notes changed the page title date from "25. July 2026" to "26th July 2026". The diff reflects a documentation update rather than a new vulnerability disclosure or exploitation event.
The OpenWrt 24.10 release page was updated to identify v24.10.8 as the latest release in the series, replacing v24.10.7. The page states that version 24.10.8 was released on 26 July 2026.
OpenWrt released stable version 24.10.8 and said it fixes many security issues, including several remotely triggerable flaws in default-enabled network services. The project strongly recommended upgrading and noted the 24.10 series had entered security-maintenance mode.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourceinfosecwriteups.com
Open sourceopenwrt.org
Open sourceopenwrt.org
Open sourcefirst.org
Open sourceopenwrt.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.