Web Hack List

Collected research

Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection

Chains command injection in OpenWrt's package build infrastructure with a practical collision against a truncated package-cache hash. An attacker can poison cached build inputs and influence generated firmware, creating a supply-chain compromise path.

Record

Researcher
RyotaK
Published by
GMO Flatt Security Research
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host.