2024. dec. 10.
Biztonsági szemle
Critical OpenWrt bug enabling malicious firmware image installation addressed
Such a flaw, which could be exploited without authentication, stems from a command injection issue in Imagebuilder that enables arbitrary command injections in the build process and truncated SHA-256 hash collisions that allow reduced entropy that ultimately results in artifact cache compromise, according to OpenWrt.