CVE-2026-30871Disclosure(openwrt / openwrt)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dn_expand into an 8096-byte global buffer (name_buffer), which is then copied via an unbounded strcpy into a fixed 256-byte stack buffer when handling TYPE_PTR queries. The overflow is possible because dn_expand converts non-printable ASCII bytes (e.g., 0x01) into multi-character octal representations (e.g., \001), significantly inflating the expanded name beyond the stack buffer's capacity. A crafted DNS packet can exploit this expansion behavior to overflow the stack buffer, making the vulnerability reachable through normal multicast DNS packet processing. This issue has been fixed in versions 24.10.6 and 25.12.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openwrt

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
openwrt

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-19: 1Mentions · 2026-03-20: 2Mentions · 2026-03-30: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-30: 103-1903-2003-30
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-191
Disclosure1
2026-03-202
Disclosure2
2026-03-301
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30871 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vu… https://www.cve.org/CVERecord?id=CVE-2026-30871

    Post summary

    The post announces CVE-2026-30871, a stack-based buffer overflow in OpenWrt's mdns daemon affecting releases prior to 24.10.6 and 25.12.1.

    11010236
    56.8K followersView on X
  • 777@SteveAJ777
    Disclosure

    U might wanna check these out The "OpenWrt mDNS" Stack Overflow (CVE-2026-30871) This is the big one for today. A 9.8 Critical vulnerability was just disclosed affecting the mdns daemon on OpenWrt. •The Vulnerability: An attacker can send a specially crafted DNS packet (via UDP port 5353) that triggers a stack-based buffer overflow. •The Risk: Since mDNS is often enabled by default for "Easy Discovery" of devices on a local network, an attacker on your Wi-Fi (or a compromised device) could potentially gain full control of the router. The "NetScaler-Style" Memory Leak (CVE-2026-3055) While this specifically targets Citrix NetScaler, researchers today are reporting active "Reconnaissance" (probing) across the internet for similar memory-overread flaws in other gateway appliances. •This exploit allows unauthenticated attackers to "leak" sensitive data from the system's memory. Linux Kernel "Transparent Huge Pages" Flaw (CVE-2026-23375) Published just hours ago, this is a local privilege escalation flaw in the Linux kernel's memory management. •The Risk: It involves a logic flaw in how the kernel handles "Secret Memory" (secretmem). A local user could potentially crash the kernel or elevate their privileges.

    Post summary

    The statement announces three new CVEs affecting OpenWrt, Citrix NetScaler, and the Linux kernel, detailing their technical nature and potential impact while lacking any PoC, exploit, patch, or evidence of current exploitation.

    0000083
    190 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-30871 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vu… https://www.cve.org/CVERecord?id=CVE-2026-30871 ----- Traducción: CVE-2026-30871 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-30871, describing a stack-based buffer overflow in OpenWrt’s MDNS daemon for versions prior to 24.10.6 and 25.12.1, with no additional exploitation or mitigation details.

    0000070
    61 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30871: OpenWrt Project has Stack-based ... Octal expansion in dn_expand turns 1-byte payloads into 4-byte sequences, amplifying crafted PTR queries 32x to smash O... https://zerodaysignal.com/vulnerability/CVE-2026-30871 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-30871 is a stack‑based buffer overflow in the OpenWrt project caused by octal expansion in dn_expand, enabling 32× amplification of crafted PTR queries.

    0000074
    154 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSopenwrtopenwrt---

Explore more