A critical, pre-authentication remote root exploit exists in OpenWRT, though the article withholds the specific attack vector and technical details for future publication. The reported CVSS score is 9.6. The affected and patched versions are not provided in the source material.
hacker.house (@hackerfantastic): "Don't believe that this is real? OpenWRT pre-auth remote root exploit 0day (CVSS 9.6, CRITICAL). Submitted this morning to the project. Technical details with-held for future publication. I have so far ran against OpenWRT, Horde, Django, WordPress, Gitlab, Dropbear & more." | XCancel