A security engineer discovered a vulnerability in the OpenWrt supply chain, specifically in the sysupgrade.openwrt.org service, which allowed for command injection and SHA-256 collision attacks. The engineer was able to exploit these vulnerabilities to compromise the service and potentially force users to upgrade to malicious firmware. The issue was reported to the OpenWrt team, who fixed the vulnerabilities within three hours. The engineer's write-up of the exploit provides a detailed look at the vulnerabilities and how they were exploited.