Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-53921 — CVE-2026-53921 | Kitploit
Tools/GitHubGitHub/0xblackash/cve-2026-53921
IoT SecurityVulnerability AnalysisPapers & ResearchLearning & Education
GitHub0xblackash/cve-2026-53921

CVE-2026-53921

CVE-2026-53921

View Repository
241 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🚨 CVE-2026-53921 - odhcpd

ChatGPT Image Jul 28, 2026, 02_52_27 PM

Critical Stack-Based Buffer Overflow in OpenWrt odhcpd

Severity CVSS Attack Impact Platform

A remote unauthenticated stack-based buffer overflow allowing potential Remote Code Execution (RCE) with root privileges.


📖 Overview


⚡ Description

CVE-2026-53921 is a critical stack-based buffer overflow affecting the OpenWrt DHCPv6 server (odhcpd).

A remote, unauthenticated attacker can send a specially crafted DHCPv6 REQUEST packet to trigger memory corruption, potentially leading to arbitrary code execution with root privileges or a Denial of Service (DoS).

Because odhcpd executes with root privileges, successful exploitation may result in complete device compromise.


🎯 Impact

root@kitploit:~
✓ Remote Code Execution (RCE)
✓ Root Privilege Compromise
✓ Memory Corruption
✓ Device Takeover
✓ Denial of Service (DoS)

🛠 Affected Component

root@kitploit:~
OpenWrt
└── odhcpd
    └── DHCPv6 Server

✅ Fixed Versions

VersionStatus
< 24.10.8❌ Vulnerable
24.10.8✅ Fixed
25.12.5+✅ Fixed

🛡 Mitigation

  • Upgrade to a patched OpenWrt release.
  • Restrict DHCPv6 exposure to trusted networks.
  • Monitor DHCPv6 traffic for anomalies.
  • Apply vendor security updates immediately.

📊 Risk Assessment


🔗 References

  • OpenWrt Security Advisory
  • CVE Record
  • National Vulnerability Database (NVD)

⚠️ Update immediately if your OpenWrt deployment exposes DHCPv6 services.

Download Tool
PropertyValue
CVE IDCVE-2026-53921
Severity🔴 Critical
CVSS v3.19.8
CWECWE-121 (Stack-Based Buffer Overflow)
Attack VectorNetwork
AuthenticationNone
User InteractionNone
Affected Componentodhcpd (DHCPv6 Server)
ImpactRemote Code Execution / Denial of Service
MetricValue
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh