Compromising OpenWrt Supply Chain via Truncated SHA-256 Collision and Command Injection Posted on December 6, 2024 • 11 minutes • 2240 words Table of contents Introduction sysupgrade.openwrt.org Command injection SHA-256 collision Brute-forcing the SHA-256 Combining both attacks Reporting the issue Conclusion Shameless plug Introduction Hello, I’m RyotaK (@ryotkak ), a security engineer at Flatt S