CVE-2026-30872Disclosure(openwrt / openwrt)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the match_ipv6_addresses function, triggered when processing PTR queries for IPv6 reverse DNS domains (.ip6.arpa) received via multicast DNS on UDP port 5353. During processing, the domain name from name_buffer is copied via strcpy into a fixed 256-byte stack buffer, and then the reverse IPv6 request is extracted into a buffer of only 46 bytes (INET6_ADDRSTRLEN). Because the length of the data is never validated before this extraction, an attacker can supply input larger than 46 bytes, causing an out-of-bounds write. This allows a specially crafted DNS query to overflow the stack buffer in match_ipv6_addresses, potentially enabling remote code execution. This issue has been fixed in versions 24.10.6 and 25.12.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • openwrt

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
openwrt

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-19: 1Mentions · 2026-03-20: 1Technical Details · 2026-03-19: 1Technical Details · 2026-03-20: 103-1903-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30872 OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vu… https://www.cve.org/CVERecord?id=CVE-2026-30872

    Post summary

    The OpenWrt mdns daemon has a stack‑based buffer overflow in versions prior to 24.10.6 and 25.12.1.

    00000176
    56.8K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-30872: OpenWrt Project has a Stack-base... Remote stack smash via crafted mDNS PTR queries - 46-byte buffer, no bounds checking, strcpy() straight to RCE on milli... https://zerodaysignal.com/vulnerability/CVE-2026-30872 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a stack‑based buffer overflow vulnerability (CVE‑2026‑30872) in OpenWrt that allows remote code execution via malformed mDNS PTR queries, linking to a vulnerability page for further details.

    0000080
    154 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
OSopenwrtopenwrt---

Explore more