logo

OpenWrt orders router firmware updates after supply chain attack scare

ID: 8caac41d-be72-5d34-8928-d8cfde9922fd

STIX ID: report--8caac41d-be72-5d34-8928-d8cfde9922fd

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2024-12-09

Date Updated: 2026-04-26

Author: Connor Jones

...
...

OpenWrt disclosed a high-severity supply-chain vulnerability in its attended sysupgrade (ASU) workflow: Imagebuilder fails to sanitize package names (command injection) and the build request uses a truncated 12-character SHA-256 hash, allowing hash collisions. Combined, these flaws could let an attacker poison the artifact cache and serve compromised firmware images; official images were reported unaffected, no signing keys were exposed, and fixes and mitigation commits have been published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.