OpenWrt Security - Overview

This page gives an overview of the security issues addressed in OpenWrt firmware. For a more detailed developer-level review of OpenWrt Security, see the developer guide at: security

[is this true?] We look to the threat model of EFF OpenWireless project for guidance:

a) An attacker using the public Internet to reach the router directly, trying to gain access to the admin UI or execute code on the router.

b) An attacker running a malicious website on the public Internet, trying to use XSS, CSRF, or similar attacks that use the router admin's logged-in session to change settings in the admin UI.

c) An eavesdropper near the router, trying to read private communications or gain access to the private network.

d) An attacker near the router who knows the private network password, trying to change settings in the admin UI or execute code on the router.

A recent study from CITL ( indicates that vendors of router firmware, “Aren't even trying.” This section describe some of the concerns that their report identifies, and how OpenWrt addresses them.

