logo

OpenWrt Sysupgrade flaw let hackers push malicious firmware images

ID: 75d3b2e2-b09c-57b5-8fc8-4ceded2bf9e6

STIX ID: report--75d3b2e2-b09c-57b5-8fc8-4ceded2bf9e6

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-12-09

Date Updated: 2026-03-27

Author: Bill Toulas

...
...

A Flatt Security researcher discovered a critical OpenWrt vulnerability (CVE-2024-54143) in the Attended Sysupgrade service that combined command injection via package names with a 12-character truncated SHA-256 cache key, enabling an attacker to craft cache collisions and deliver malicious custom firmware. OpenWrt took the service offline, patched the flaw within hours, and found no evidence of exploitation; users are advised to reinstall newly generated images and update any self-hosted ASU instances to eliminate residual risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.