SECURITY·중요도 9·2026. 07. 28.·The Hacker News
Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
── KO ──────────────────
OpenWrt의 DHCPv6 취약점이 원격 코드 실행을 허용할 수 있다는 경고.
OpenWrt는 24.10.8 버전을 출시하여 DHCPv6 스택 오버플로우와 기타 원격에서 트리거할 수 있는 문제를 해결했습니다. 이 취약점은 CVE-2026-53921로 추적되며, CVSS 3.1에서 9.8의 높은 평가를 받았습니다. 인증되지 않은 공격자가 DHCPv6 서버에 접근하여 odhcpd에서 스택 버퍼를 덮어쓸 수 있는 위험이 존재합니다.
── EN ──────────────────
A critical DHCPv6 vulnerability in OpenWrt allows unauthenticated attackers to execute code as root.
OpenWrt has released version 24.10.8 to address a critical DHCPv6 stack overflow and other remotely triggerable flaws. This vulnerability, tracked as CVE-2026-53921, is rated 9.8 on the CVSS 3.1 scale. Unauthenticated attackers could reach the DHCPv6 server to overwrite a stack buffer in odhcpd, posing a significant security risk.