https://flatt.tech/research/posts/compromising-openwrt-supply-chain-sha256-collision/
OpenWrt Supply Chain Attack in Attended Sysupgrade server
如果冇用attendedsysupgrade/owut既話, 應該唔受影響? OpenWrt developer咁講:
NO OFFICIAL IMAGES from the downloads.openwrt.org were AFFECTED nor any custom images from 24.10.0-rc2.
即是直接係OpenWrt官網Download官方Image, 又或者去Firmware selector直接Download vanilla image (即是冇做custom build) 既話應該冇事
怕既話, 官方建議做inplace upgrade to the same version (i.e. flash同一版本既firmware)