<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — OpenWrt</title><description>Security vulnerabilities in OpenWrt, the open-source Linux-based firmware widely deployed in consumer routers, small-business gateways, and embedded network devices. Flaws in OpenWrt affect the underlying routing and DHCPv6/DNS infrastructure of countless home and enterprise networks. Combined article + CVE feed for the OpenWrt beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Three Critical OpenWrt LuCI Flaws Allow Root RCE</title><link>https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-15-openwrt-luci-critical-root-rce/</guid><description>Two CVSS 9.9 and one 8.8 vulnerabilities in OpenWrt&apos;s LuCI web interface let authenticated users execute arbitrary code as root. Update LuCI now.</description><pubDate>Sat, 15 Aug 2026 06:00:00 GMT</pubDate><category>OpenWrt</category><category>article</category></item><item><title>CVE-2026-72840 — OpenWrt LuCI Mount App ACL Misconfiguration Grants Root Cron Write</title><link>https://0daynews.com/cve/cve-2026-72840/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-72840/</guid><description>luci-mod-system-mounts ACL grants /etc/crontabs/root write access to mount-config users, enabling cron injection executed as root within one minute. CVSS 8.8 high.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>OpenWrt</category><category>high</category><category>cve</category></item><item><title>CVE-2026-72841 — OpenWrt LuCI OpenVPN App Path Traversal Enables Root RCE</title><link>https://0daynews.com/cve/cve-2026-72841/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-72841/</guid><description>luci-app-openvpn path traversal on file upload enables persistent root code execution on OpenWrt routers by writing arbitrary files to system paths. CVSS 9.9 critical.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>OpenWrt</category><category>critical</category><category>cve</category></item><item><title>CVE-2026-72842 — OpenWrt LuCI Container App ACL Bypass Leads to Root RCE</title><link>https://0daynews.com/cve/cve-2026-72842/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2026-72842/</guid><description>luci-app-lxc ACL inconsistency lets low-privileged authenticated users exploit path traversal to achieve root code execution on the OpenWrt host. CVSS 9.9 critical.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate><category>OpenWrt</category><category>critical</category><category>cve</category></item><item><title>OpenWrt Patches Critical DHCPv6 RCE in Default Server</title><link>https://0daynews.com/articles/2026-07-28-openwrt-24-10-8-dhcpv6-rce-critical/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-28-openwrt-24-10-8-dhcpv6-rce-critical/</guid><description>OpenWrt 24.10.8 patches a critical stack overflow in odhcpd — the DHCPv6 server enabled by default — allowing unauthenticated RCE as root. Patch now.</description><pubDate>Tue, 28 Jul 2026 18:00:00 GMT</pubDate><category>OpenWrt</category><category>article</category></item></channel></rss>