[OpenWrt Wiki] Security
https://openwrt.org/docs/guide-developer/security/old22.10.2019 · Security bugs seem to not be treated differently than other kinds of bugs, so one should probably follow the normal bug reporting procedures documented in the bugs wiki page. On the other hand, the mailing list thread [OpenWrt-Devel] Security Vulnerability Reporting and Database indicated that security vulnerabilities be reported by sending an email to the public …
OpenWrt Forum Archive
https://forum.archive.openwrt.org/viewtopic.php?id=1425&p=104.05.2005 · Are there any notable security concerns running dnsmasq as root? Generally speaking, any daemon running as root represents a chance for an attacker to exploit some still unknown security hole (typically, a chance for a buffer overflow somewhere) in order to run malicious code with superuser privilege, and take over the machine.
[OpenWrt Wiki] Security
https://openwrt.org/docs/guide-developer/securityA OpenWrt major version will get into fully supported status after it was initially released. When the next OpenWrt major version is released the old version will move into security maintenance mode. A OpenWrt major version will move into end of Life 1 year after the initial release or 6 months after the release of the next major versions.
[OpenWrt Wiki] OpenWrt Security Advisories
https://openwrt.org/advisory26.01.2020 · OpenWrt Security Advisories * Security Advisory 2021-08-01-3 - luci-app-ddns: Multiple authenticated RCEs (CVE-2021-28961) * Security Advisory 2021-08-01-2 - Stored XSS in hostname UCI variable (CVE-2021-33425) * Security Advisory 2021-08-01-1 - XSS via missing input validation of host names displayed (CVE-2021-32019) * Security Advisory 2021-02-02-2 - …