PT-2026-56265 · Openwrt · Openwrt

·

CVE-2026-55490

·

Published

2026-07-07

·

Updated

2026-07-08

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenWrt versions prior to 25.12.5
Description An integer underflow occurs in the handle send a() function of the Emergency Access Daemon. An unauthenticated attacker on the local network can trigger this by sending a single crafted UDP packet, causing the message length to underflow before a bounds check. This underflowed value is subsequently passed to memcpy as an excessively large size, resulting in a daemon crash.
Recommendations Update to version 25.12.5.

Exploit

Fix

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55490
GHSA-9558-77JP-G3FW

Affected Products

Openwrt