CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability

Published Jul 16, 2026
·
Updated

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdpmsearch (reachable by an M-SEARCH request).

Other sources

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

CISA

Affected Software

3 affected components
router/upnp/src/ssdp.c in DD-WRT<45724
DD-WRT DD-WRT
DD-WRT DD-WRT<45724

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade DD-WRT/router/upnp/src/ssdp.c to a version that resolves this vulnerability.

    Fixed in 45724
  2. Configuration

    Ensure UPnP is disabled (UPnP is off by default; exploitation requires the DD-WRT user to enable UPnP).

    DD-WRT UPnP UPnP = disable
  3. Compensating control

    Ensure UPnP exposure is limited to internal interfaces only (UPnP listens on internal interfaces by default; avoid exposing UPnP/SSDP to the internet).

  4. Operational

    If UPnP was enabled and potentially reachable, evaluate whether any compromise indicators exist and perform incident-response/forensics triage in accordance with CISA’s “Forensics Triage Requirements”.

Event History

Jun 7, 2026
News Published
via BleepingComputer·02:17 PM
News Published
via BleepingComputer·02:24 PM
Jul 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 21, 2026
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2021-27137?

CVE-2021-27137 has a severity score of 8.1, indicating a high risk vulnerability.

2

How do I fix CVE-2021-27137?

To fix CVE-2021-27137, disable UPnP on your DD-WRT router or update to a patched version after 45724.

3

What type of vulnerability is CVE-2021-27137?

CVE-2021-27137 is a stack-based buffer overflow vulnerability affecting the UPnP functionality.

4

Who is affected by CVE-2021-27137?

Users of DD-WRT firmware versions before 45724 that have UPnP enabled are vulnerable to CVE-2021-27137.

5

Can CVE-2021-27137 be exploited remotely?

Yes, CVE-2021-27137 can be exploited by an unauthenticated remote attacker if UPnP is enabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203