
CVE-2026-53921
odhcpd
odhcpd
A remote unauthenticated stack-based buffer overflow allowing potential Remote Code Execution (RCE) with root privileges.
CVE-2026-53921 is a critical stack-based buffer overflow affecting the OpenWrt DHCPv6 server (odhcpd).
A remote, unauthenticated attacker can send a specially crafted DHCPv6 REQUEST packet to trigger memory corruption, potentially leading to arbitrary code execution with root privileges or a Denial of Service (DoS).
Because odhcpd executes with root privileges, successful exploitation may result in complete device compromise.
✓ Remote Code Execution (RCE)
✓ Root Privilege Compromise
✓ Memory Corruption
✓ Device Takeover
✓ Denial of Service (DoS)
OpenWrt
└── odhcpd
└── DHCPv6 Server
| Version | Status |
|---|---|
| < 24.10.8 | ❌ Vulnerable |
| 24.10.8 | ✅ Fixed |
| 25.12.5+ | ✅ Fixed |
| Property | Value |
|---|
| CVE ID | CVE-2026-53921 |
| Severity | 🔴 Critical |
| CVSS v3.1 | 9.8 |
| CWE | CWE-121 (Stack-Based Buffer Overflow) |
| Attack Vector | Network |
| Authentication | None |
| User Interaction | None |
| Affected Component | odhcpd (DHCPv6 Server) |
| Impact | Remote Code Execution / Denial of Service |
| Metric | Value |
|---|
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Scope | Unchanged |
| Confidentiality | High |
| Integrity | High |
| Availability | High |