CRITICAL: OpenWrt DHCPv6 Flaw CVE-2026-53921 Gives Root Without Auth
OpenWrt disclosed CVE-2026-53921, a pair of stack buffer overflows in the odhcpd DHCPv6 daemon that let an unauthenticated attacker reach code execution as root on affected devices. It scores CVSS 9.8 and is fixed in OpenWrt 24.10.8 and 25.12.5. No exploitation has been reported yet, but public proof of concept code already exists.