← Vulnerability feed

Vulnerability record · CVE-2026-30871 · published 19 March 2026

CVE-2026-30871: Openwrt stack-based buffer overflow vulnerability

Openwrt · Openwrt

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dn_expand into an 8096-byte global buffer (name_buffer), which is then copied via an unbounded strcpy into a fixed 256-byte stack buffer when handling TYPE_PTR queries. The overflow is possible because dn_expand converts non-printable ASCII bytes (e.g., 0x01) into multi-character octal representations (e.g., \001), significantly inflating the expanded name beyond the stack buffer's capacity. A crafted DNS packet can exploit this expansion behavior to overflow the stack buffer, making the vulnerability reachable through normal multicast DNS packet processing. This issue has been fixed in versions 24.10.6 and 25.12.1.

9.5 CVSS 4.0 Critical EPSS 0.67% · top 50.0% CWE-121 · Stack-based buffer overflow
9.5CVSS 4.0 base score
0.67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dn_expand into an 8096-byte global buffer (name_buffer), which is then copied via an unbounded strcpy into a fixed 256-byte stack buffer when handling TYPE_PTR queries. The overflow is possible because dn_expand converts non-printable ASCII bytes (e.g., 0x01) into multi-character octal representations (e.g., \001), significantly inflating the expanded name beyond the stack buffer's capacity. A crafted DNS packet can exploit this expansion behavior to overflow the stack buffer, making the vulnerability reachable through normal multicast DNS packet processing. This issue has been fixed in versions 24.10.6 and 25.12.1.

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-30871 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-20681Mediatek software development kit out-of-bounds write vulnerabilityIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with Us…EPSS 0.54%9.8CVE-2025-20682Mediatek software development kit out-of-bounds write vulnerabilityIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with Us…EPSS 0.48%9.8CVE-2025-20683Mediatek software development kit out-of-bounds write vulnerabilityIn wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with Us…EPSS 0.48%9.8CVE-2025-20674Openwrt incorrect authorization vulnerabilityIn wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of priv…EPSS 0.77%9.8CVE-2025-20654Mediatek software development kit out-of-bounds write vulnerabilityIn wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additiona…EPSS 0.81%9.8CVE-2024-20017MediaTek wlan service out-of-bounds write allows remote code executionThe MediaTek wlan service fails to properly validate input, leading to an out-of-bounds write. This flaw can be triggered remotely without authentica…EPSS 47%analysed9.8CVE-2020-28951Openwrt use after free vulnerabilitylibuci in OpenWrt before 18.06.9 and 19.x before 19.07.5 may encounter a use after free when using malicious package names. This is related to uci_pa…EPSS 1.8%9.6CVE-2026-62948Openwrt cross-site scripting vulnerabilityOpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh…EPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2026-30871), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.