CVE-2026-30871
Last modified
CVE-2026-30871 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
OpenWrt Project is a Linux operating system targeting embedded devices. In versions prior to 24.10.6 and 25.12.1, the mdns daemon has a Stack-based Buffer Overflow vulnerability in the parse_question function. The issue is triggered by PTR queries for reverse DNS domains (.in-addr.arpa and .ip6.arpa). DNS packets received on UDP port 5353 are expanded by dn_expand into an 8096-byte global buffer (name_buffer), which is then copied via an unbounded strcpy into a fixed 256-byte stack buffer when handling TYPE_PTR queries. The overflow is possible because dn_expand converts non-printable ASCII bytes (e.g., 0x01) into multi-character octal representations (e.g., \001), significantly inflating the expanded name beyond the stack buffer's capacity. A crafted DNS packet can exploit this expansion behavior to overflow the stack buffer, making the vulnerability reachable through normal multicast DNS packet processing. This issue has been fixed in versions 24.10.6 and 25.12.1.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Openwrt | Openwrt | < 24.10.6 |
| Openwrt | Openwrt | >= 25.12.0, < 25.12.1 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-30871?
How severe is CVE-2026-30871?
How do I fix CVE-2026-30871?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-30863Parse Server is an open source backend that can be deployed …9.8
- CVE-2026-30867CocoaMQTT is a MQTT 5.0 client library for iOS and macOS wri…6.5
- CVE-2026-30868OPNsense is a FreeBSD based firewall and routing platform. P…8.1
- CVE-2026-30869SiYuan is a personal knowledge management system. Prior to 3…9.8
- CVE-2026-3087If `shutil.unpack_archive()` is given a ZIP archive with an …7.5
- CVE-2026-30870PowerSync Service is the server-side component of the PowerS…6.5
- CVE-2026-30872OpenWrt Project is a Linux operating system targeting embedd…9.8
- CVE-2026-30873OpenWrt Project is a Linux operating system targeting embedd…4.9
- CVE-2026-30874OpenWrt Project is a Linux operating system targeting embedd…7.8
- CVE-2026-30875Chamilo LMS is a learning management system. Prior to versio…8.8
- CVE-2026-30876Chamilo LMS is a learning management system. Prior to versio…5.3
- CVE-2026-30877baserCMS is a website development framework. Prior to versio…7.2
Are you affected by CVE-2026-30871?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
