Collected research
Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection
Chains command injection in OpenWrt's package build infrastructure with a practical collision against a truncated package-cache hash. An attacker can poison cached build inputs and influence generated firmware, creating a supply-chain compromise path.
Record
- Researcher
- RyotaK
- Published by
- GMO Flatt Security Research
- Date
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host.