CVE Feed

    Dashboard / CVE / CVE-2026-55490

    CVE-2026-55490

    OpenWrt is a Linux operating system targeting embedded devices. Before v25.12.5, an integer underflow in handle_send_a() of the Emergency Access Daemon allows any unauthenticated attacker on the local network to crash the daemon by sending a single crafted UDP packet. The message length underflows before a bounds check and is then passed to memcpy as a very large size. This issue is fixed v25.12.5.

    Published:Jul 7, 2026
    Last Modified:Jul 8, 2026
    EPS:Jul 7, 2026
    EPSS Score:0.00647
    CVSS Score:6.5

    Affected Products

    Vendor
    Openwrt
    Product
    Openwrt

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High