ON
← Back to feed
heise online logo🏛️ Politics
Germany🏛️ Politics8 days ago

OpenWrt: Updates to address some critical security flaws

The open-source router firmware OpenWrt has released new versions, including 24.10.8 and 25.12.5, which address several critical security vulnerabilities. These updates close flaws that could be exploited remotely without prior authentication, some of which are present in services enabled by default. The most severe vulnerability is a buffer overflow in the odhcpd DHCP server, which allows attackers to execute arbitrary code via a single UDP packet. Another issue enables unauthorized modification of lease files through manipulated FQDN hostnames, leading to a stored cross-site scripting flaw in the LuCI interface. Additional fixes include patches for LuCI, dropbear-SSH, and updated components like OpenSSL, dnsmasq, and the Linux kernel. Users running OpenWrt are advised to update their devices promptly to reduce exposure to potential attacks.

OpenWrt has released updated firmware versions addressing several critical security vulnerabilities, some of which can be exploited remotely without prior authentication. The open-source router firmware, known for its flexibility and customization options, now includes patches for issues affecting both the 24.10.8 release from last weekend and the 25.12.5 version released earlier this month. These updates address multiple flaws, including those present in services that are typically enabled by default. The most severe vulnerability identified is within the odhcpd DHCP server, which is active by default on many devices running OpenWrt. This flaw allows attackers to trigger a stack overflow when processing DHCPv6 IA responses via a single UDP packet. The lack of Address Space Layout Randomization (ASLR) on embedded platforms makes it easier for malicious code to execute, increasing the risk of exploitation. This vulnerability is assigned the identifier CVE-2026-53921 with a CVSS score of 9.8 and is classified as critical. Another related issue in odhcpd enables unauthenticated DHCPv6 clients to inject manipulated FQDN hostnames into lease files, leading to a stored cross-site scripting (XSS) vulnerability in the LuCI DHCPv6 leases status page, labeled CVE-2026-62948 with a CVSS score of 9.6 and critical risk rating. Additional fixes target the LuCI web interface, resolving further stored XSS vulnerabilities rated as high risk. A patch for the dropbear-SSH component addresses a long-standing vulnerability dating back to 2019. Updated components such as OpenSSL 3.0.21, dnsmasq 2.93, and the Linux kernel 6.6.144 also contribute to closing multiple security gaps. Users running OpenWrt should apply these updated firmware builds to their devices promptly to reduce exposure to potential attacks. Since OpenWrt is often accessible from the internet, timely updates are crucial. The firmwares are designed to minimize attack surfaces and ensure continued secure operation. In March, the OpenWrt 25.12.0 branch introduced a switch to a new package manager, enhancing system management capabilities. Additionally, this version supports more device models than previous releases, expanding compatibility and usability. These changes reflect ongoing efforts to improve both functionality and security within the OpenWrt ecosystem. The updates underscore the importance of regular maintenance and patching in securing network infrastructure. As more users rely on OpenWrt for home and small business networking, staying current with firmware updates becomes essential. The community-driven nature of OpenWrt ensures that security concerns are addressed through collaborative development and rapid response mechanisms. Users are encouraged to monitor official channels for future advisories and to implement best practices for network security.

Go to the primary sources (3)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 85Objective 808 days ago
OpenWrt: Updates to address some critical security flaws

The open-source router firmware OpenWrt has released new versions, including 24.10.8 and 25.12.5, which address several critical security vulnerabilities. These updates close flaws that could be exploited remotely without prior authentication, some of which are present in services enabled by default. The most severe vulnerability is a buffer overflow in the odhcpd DHCP server, which allows attackers to execute arbitrary code via a single UDP packet. Another issue enables unauthorized modification of lease files through manipulated FQDN hostnames, leading to a stored cross-site scripting flaw in the LuCI interface. Additional fixes include patches for LuCI, dropbear-SSH, and updated components like OpenSSL, dnsmasq, and the Linux kernel. Users running OpenWrt are advised to update their devices promptly to reduce exposure to potential attacks.

Bias read (Center): The article reports on technical updates and security patches for OpenWrt, a software project with no political affiliation. It presents factual information about vulnerabilities and fixes without taking a partisan stance. The tone remains neutral, focusing on technical details rather than advocacy,

Why factuality (85): The article accurately reports the release of OpenWrt 24.10.8 and highlights key security fixes, including critical vulnerabilities like CVE-2026-53921 and CVE-2026-62948. It references the primary source document and aligns with the official announcement regarding security updates and EoL dates. Ho

Why objectivity (80): The tone remains professional and informative, focusing on the technical aspects of the update. While it presents the information objectively, there is a slight emphasis on the severity of the security flaws, which may be seen as slightly more dramatic than a purely neutral report.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories