Hacker House Discloses Multiple OpenWrt Zero-Days Allowing Unauthenticated Root Access
Hacker House disclosed multiple remote zero-day vulnerabilities in the OpenWrt software platform that enable unauthenticated command execution with root privileges on connected routers.
The primary flaw targets the DHCPv6 service, allowing crafted network requests to execute code without a login, while a separate audit identified seven additional vulnerabilities. The group confirmed that software patches are now shipping to address the security issues across millions of routers worldwide.
From the sources (3 posts)
@myhackerhouse🚨Multiple remote OpenWrt 0days disclosed by Hacker House - pre-auth to full device compromise, command execution as root on millions of routers worldwide. Fixes shipping now. Here's how our inference-fuzzing methodology found them, via @The
@hackerfantasticMultiple remote OpenWrt 0days. Pre-auth paths straight to full device compromise. Unauthenticated command execution as root on millions of routers. Fixes shipping now. No login. No session. Remote root. Full breakdown via @TheHackersNews @m
@thehackersnews⚠️ ALERT - OpenWrt users, this one needs attention. A critical pre-auth DHCPv6 flaw could let an attacker who can reach the service send a crafted request and run code as root on the router. A separate audit also found 7 more flaws, inclu