Hi,
The OpenWrt community is proud to announce the newest stable release of the OpenWrt 24.10 stable series.
This release fixes many security issues, several of them remotely triggerable in network services that are enabled by default. We strongly recommend everyone to upgrade.
The OpenWrt 24.10 series is in security maintenance (only security problems are fixed), with end of life (EoL) projected for September 2026. We recommend migrating to OpenWrt 25.12 before then.
Download firmware images using the OpenWrt Firmware Selector:
Download firmware images directly from our download servers:
Main changes between OpenWrt 24.10.7 and OpenWrt 24.10.8
Only the main changes are listed below. See changelog-24.10.8 for the full changelog.
Security fixes
This release fixes several remotely triggerable vulnerabilities in core network
services that are enabled by default. Updating is strongly recommended.
- odhcpd (DHCPv6/DHCPv4/RA server, enabled by default): multiple vulnerabilities reachable by a network-adjacent, unauthenticated attacker were fixed:
- CVE-2026-53921 (Critical): stack buffer overflow in the DHCPv6 IA reply serialization, triggerable with crafted DHCPv6 REQUEST packets.
GHSA-7fwx-hhrg-3496 - Reconfigure-Accept stack buffer overflow (High, no CVE assigned): the Reconfigure-Accept reply block wrote 36 bytes into the response buffer without checking the remaining space, leading to a pre-auth out-of-bounds write.
https://github.com/openwrt/openwrt/security/advisories/GHSA-q6wx-p68j-chp9 - CVE-2026-53918 (High): use-after-free through a dangling first-lease pointer in the DHCPv6 IA handler.
GHSA-44ff-jcwh-wgc2 - CVE-2026-53920 (High): stack memory disclosure via a truncated DHCPv6 IA_NA/IA_PD option.
GHSA-p769-5v73-pc4f - CVE-2026-53922 (Moderate): pre-auth denial of service via a size_t underflow in DHCPv6 IA handling.
GHSA-7hcw-g2jh-pqv5 - Zero-length CLIENT_ARCH option (Moderate, no CVE assigned): stack buffer over-read, and an unaligned read that crashes on strict-alignment targets.
https://github.com/openwrt/odhcpd/security/advisories/GHSA-7x9h-5mxm-jg3f - NDP hop-limit spoofing (Moderate, CVSS 5.4, no CVE assigned): the NDP relay accepted IPv6 Neighbor Solicitations with a hop limit other than 255 (RFC 4861 violation), letting an off-link attacker spoof NS packets through the relay. Only relevant when the NDP relay is enabled.
https://github.com/openwrt/odhcpd/security/advisories/GHSA-qvg7-9jf5-wgjc
- CVE-2026-53921 (Critical): stack buffer overflow in the DHCPv6 IA reply serialization, triggerable with crafted DHCPv6 REQUEST packets.
- odhcpd / LuCI stored XSS: CVE-2026-62948 (Critical): an unauthenticated DHCPv6 client could inject lease-file lines through a crafted FQDN hostname, resulting in stored cross-site scripting on the LuCI DHCPv6 leases status page. Fixed by escaping client hostnames in the lease state file.
GHSA-hhmc-92hw-535f - uhttpd (web server, serves LuCI): three HTTP request smuggling issues on keep-alive connections were fixed:
- CVE-2026-55614 (High): case-sensitive Transfer-Encoding matching.
GHSA-mcfg-c4r7-pjpf - CVE-2026-55612 (High): invalid chunk-length state reset.
GHSA-p55c-rmhc-qfm5 - CVE-2026-55613 (Moderate): ubus POST body parse-error desync.
GHSA-wgwp-64hh-f52p - In addition uhttpd received hardening without an assigned CVE: a one-byte overflow in
uh_urldecode(), an off-by-one out-of-bounds read inuh_b64decode(), constant-time password comparison and stricter handling of$p$crypt-hash entries in the authentication realm.
- CVE-2026-55614 (High): case-sensitive Transfer-Encoding matching.
- rpcd: ACL bypass through symlinks (High): the
fileplugin matched ACL grants against the textual path but then followed symlinks unchecked, so a symlink inside an ACL-covered directory let a limited account read or write arbitrary root-owned files. The path is now re-resolved and re-authorized for every operation that dereferences the final component.
https://github.com/openwrt/openwrt/security/advisories/GHSA-q5gr-86pq-vvwr - cgi-io (file upload/download helper used by LuCI, installed by default with LuCI):
- CVE-2026-62947 (Moderate): ACL bypass and arbitrary root file read β the download and exec paths were checked against the ACL before being canonicalized, so path traversal let an authenticated user with wildcard read permission read any root-readable file (e.g.
/etc/shadow).
GHSA-jw5r-xhf5-2xcq - Use-after-free (Moderate, no CVE assigned): decoding malformed percent-encoded POST field data could use freed memory.
https://github.com/openwrt/openwrt/security/advisories/GHSA-wvhq-qmwj-grj2
- CVE-2026-62947 (Moderate): ACL bypass and arbitrary root file read β the download and exec paths were checked against the ACL before being canonicalized, so path traversal let an authenticated user with wildcard read permission read any root-readable file (e.g.
- LuCI (web interface): several issues in LuCI modules and applications were fixed. The privilege-escalation issues only apply if the affected app is installed and a limited (delegated) account with the relevant ACL exists:
- luci-app-ddns (High): the ucode status backend passed DDNS UCI values such as
lookup_host,dns_serverand the section name tosystem()as an unquoted shell string, so anyone able to write DDNS configuration could execute commands as root. The invocations now use the array form ofsystem().
https://github.com/openwrt/openwrt/security/advisories/GHSA-32r4-3wh2-qvq3 - luci-app-samba4 (High): the read ACL granted exec permission for
smbdin general rather than onlysmbd -V, allowing read-only accounts to run arbitrary commands as root.
GHSA-vx64-mmp7-h36c - luci-app-upnp (High): stored XSS β an unauthenticated LAN client can inject JavaScript through a UPnP port-mapping description, which the underlying daemon does not sanitize. The description is now HTML-escaped.
GHSA-8v49-6387-7f89 - luci-mod-status (High): stored XSS via a DHCP/DHCPv6 lease hostname shown in the lease status tables. Together with the odhcpd fix above this closes the injection path from an unauthenticated DHCP client into the LuCI admin UI.
GHSA-686p-p8p9-x6fh - luci-base: the dispatcher now escapes the URL path and user name when logging, so crafted login requests can no longer pollute the system log.
- The LuCI rpcd ACL files were adjusted for the symlink-aware rpcd ACL check mentioned above, so that
/procpaths that are symlinks (such as/proc/mounts) keep working.
- luci-app-ddns (High): the ucode status backend passed DDNS UCI values such as
- umdns (mDNS responder): CVE-2026-55492 (Moderate, CVSS 6.5): an unauthenticated attacker on the local network segment could flood the daemon with unique mDNS records; the unbounded cache exhausted the heap and took the whole device into out-of-memory. Fixed by bounding the cache size and clamping hostile TTLs.
GHSA-jg8f-fhfw-jg46 - ead (Emergency Access Daemon): CVE-2026-55490 (Moderate): an integer underflow in
handle_send_a()allowed an unauthenticated attacker on the local segment to crash the daemon with a single crafted packet.
GHSA-9558-77jp-g3fw - hostapd / wpa_supplicant: the fixes from upstream hostap security advisory 2026-1 were applied. Missing validation of multi-link (MLO / IEEE 802.11be) information in received Management frames could terminate the process or corrupt a small amount of memory; the frames need neither authentication nor user interaction.
https://w1.fi/security/2026-1/missing-ml-parsing-validation.txt
https://github.com/openwrt/openwrt/security/advisories/GHSA-3hj7-gj5w-h68m - dropbear (SSH): security fixes from upstream 2026.90 were backported:
- CVE-2019-6111: a malicious server could make the
scpclient overwrite unexpected local files (missing OpenSSH patch). Note the accompanying upstream behaviour change:scp -ris now rejected when the target directory already exists. - CVE-2026-35385:
scpdid not clear setuid/setgid bits on received files. - An authenticated user could bypass an
authorized_keysforced_commandoption when dropbear runs with-t;authorized_keysis now opened non-blocking (local denial of service via special files); and aclose()on a file descriptor obtained from an out-of-bounds read was fixed.
- CVE-2019-6111: a malicious server could make the
- musl libc: backport of the upstream fixes for CVE-2026-6042 (algorithmic-complexity denial of service in
iconv) and CVE-2026-40200 (stack corruption inqsortwith sufficiently large inputs). - OpenSSL: update to 3.0.21, fixing multiple security vulnerabilities (CVE-2026-45447, CVE-2026-34182, CVE-2026-45445, CVE-2026-7383, CVE-2026-9076, CVE-2026-34180, CVE-2026-42766, CVE-2026-42770, CVE-2026-45446).
- Linux kernel: update to 6.6.144, pulling in the upstream 6.6.142, 6.6.143 and 6.6.144 stable releases, which fix multiple security vulnerabilities.
- dnsmasq: update to 2.93, which carries the security fixes that were backported into 2.90 in the previous release (CVE-2026-2291, CVE-2026-4890, CVE-2026-4891, CVE-2026-4892, CVE-2026-4893 and CVE-2026-5172) plus further upstream fixes.
In addition, the packages feed shipped with this release moved a number of
optional packages to newer upstream versions that contain security fixes, among
them curl (8.12.1 to 8.19.0), expat (2.7.4 to 2.8.2), BIND (9.20.23 to 9.20.26),
PHP 8 (8.3.29 to 8.3.32), Tor (0.4.8.22 to 0.4.9.10), unbound (1.24.2 to 1.25.1),
lighttpd (1.4.82 to 1.4.85), haproxy (3.0.19 to 3.0.25) and rsync (3.4.2 to 3.4.3).
collectd also received a fix for a use-after-free in the ping plugin. These
packages are not part of the default images β you have to update the installed
packages on your device to receive them.
Beyond the issues listed above, this release fixes a number of further security
and robustness problems in odhcpd, odhcp6c, rpcd and uhttpd for which no CVE
number or dedicated advisory was assigned. We strongly recommend upgrading to
the latest OpenWrt release and installing all available package updates.
Device support
No new devices were added in this security maintenance release.
Device fixes:
- airoha: update the PCS driver to a newer proposed upstream version (EN7581 Ethernet SerDes)
- ipq806x: Extreme Networks AP3935 - disable PHY hibernation on LAN1, which otherwise stayed dead when no cable was connected at power-on
WiFi fixes and improvements
- mac80211: update the backported wireless stack and drivers from 6.12.61 to 6.12.96, containing many upstream fixes for ath10k, ath11k, rtw88, rtlwifi and iwlwifi, among them:
- ath10k: skip WMI and beacon transmission when the device is wedged
- ath11k: fix a warning on unbind and fix peer resolution on the RX path
- rtw88: fix memory leaks on USB write failures
- mac80211/nl80211: reject oversized EMA RNR lists and fix multi-link element defragmentation
- hostapd / wpa_supplicant: multi-link (MLO) parsing validation fixes, see the security section above
- wireless-regdb: update to 2026.05.30
Network and service improvements
- odhcpd received many DHCPv6/DHCPv4 correctness and robustness fixes on top of the security fixes listed above, among them bounded nested relay recursion, correct handling of DHCPv4 Pad/End option encoding, fixed reallocation error handling and a memory leak on reload
- odhcp6c: several fixes to DHCPv6 option parsing, RFC 6603 prefix-exclude handling, Reconfigure message validation and script invocation
- rpcd: fixes for a use-after-free in the async exec reply path, a double close of exec pipe descriptors, an integer overflow in the UCI apply timeout and several memory leaks
- umdns: update to a current version with the cache limits mentioned above
Other changes
- busybox: the shell command history is now saved again. To avoid flash wear, it is written only when a shell session exits and it is stored in
/tmp, so it is lost on reboot. The location can be changed in/etc/profile.d/busybox-history-file.sh.
Core components update
- Linux kernel: update from 6.6.141 to 6.6.144
- OpenSSL: update from 3.0.20 to 3.0.21 (multiple security fixes, see above)
- dnsmasq: update from 2.90 to 2.93
- mac80211: update from 6.12.61 to 6.12.96
- wireless-regdb: update from 2026.03.18 to 2026.05.30
- ca-certificates: update from 20260223 to 20260601 (refreshed root CA bundle)
Upgrading to 24.10
Sysupgrade can be used to upgrade a device from 23.05 to 24.10, and configuration will be preserved in most cases.
For for upgrades inside the OpenWrt 24.10 stable series for example from a OpenWrt 24.10 release candidate Attended Sysupgrade is supported in addition which allows preserving the installed packages too.
-
Sysupgrade from 22.03 to 24.10 is not officially supported.
-
There is no configuration migration path for users of the ipq806x target for Qualcomm Atheros IPQ806X SoCs because it switched to DSA. You have to upgrade without saving the configuration.
''Image version mismatch. image 1.1 device 1.0 Please wipe config during upgrade (force required) or reinstall. Config cannot be migrated from swconfig to DSA Image check failed'' -
User of the Linksys E8450 aka. Belkin RT3200 running OpenWrt 23.05 or earlier will need to run installer version v1.1.3 or later in order to reorganize the UBI layout for the 24.10 release. A detailed description is in the OpenWrt wiki. Updating without using the installer will break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
-
Users of the Xiaomi AX3200 aka. Redmi AX6S running OpenWrt 23.05 or earlier have to follow a special upgrade procedure described in the wiki. This will increase the flash memory available for OpenWrt. Updating without following the guide in the wiki break the device. Sysupgrade will show a warning before doing an incompatible upgrade.
-
Users of Zyxel GS1900 series switches running OpenWrt 23.05 or earlier have to perform a new factory install with the initramfs image due to a changed partition layout. Sysupgrade will show a warning before doing an incompatible upgrade and is not possible. After upgrading, the config file /etc/config/system should not be restored from a backup, as this will overwrite the new compat_version value.
-
Users of
scpfrom the dropbear package: recursive copies (scp -r) into an already existing target directory are now rejected. This is an intentional upstream change that comes with the fix for CVE-2019-6111. Usersyncor copy into a non-existing directory instead.
Known issues
- LEDs for Airoha AN8855 are not yet supported. Devices like the Xiaomi AX3000T with an Airoha switch will have their switch LEDs powered off. This will not be addressed in the OpenWrt 24.10 series any more, it is fixed in OpenWrt 25.12.
- 5GHz WiFi is non-functional on certain devices with ath10k chipsets. Affected models include the Phicomm K2T, TP-Link Archer C60 v3 and possibly others. For details, see issue #14541.
Full release notes and upgrade instructions are available at
https://openwrt.org/releases/24.10/notes-24.10.8
In particular, make sure to read the regressions and known issues before upgrading:
https://openwrt.org/releases/24.10/notes-24.10.8#known_issues
For a detailed list of all changes since 24.10.7, refer to
https://openwrt.org/releases/24.10/changelog-24.10.8
To download the 24.10.8 images, navigate to:
https://downloads.openwrt.org/releases/24.10.8/targets/
Use OpenWrt Firmware Selector to download:
https://firmware-selector.openwrt.org?version=24.10.8
As always, a big thank you goes to all our active package maintainers, testers, documenters and supporters.
Have fun!
The OpenWrt Community
To stay informed of new OpenWrt releases and security advisories, there
are new channels available:
-
a low-volume mailing list for important announcements:
https://lists.openwrt.org/mailman/listinfo/openwrt-announce -
a dedicated "announcements" section in the forum:
https://forum.openwrt.org/c/announcements/14 -
other announcement channels (such as RSS feeds) might be added in the
future, they will be listed at https://openwrt.org/contact