CVE-2021-47854: DD-WRT 45723 - UPNP Buffer Overflow
DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DD-WRTto a version that resolves this vulnerability.Fixed in 45723Patch DD-WRT 45723 - UPNP Buffer Overflow
Event History
Frequently Asked Questions
What is the severity of CVE-2021-47854?
CVE-2021-47854 is classified as a high-severity vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2021-47854?
To fix CVE-2021-47854, you should upgrade to the latest DD-WRT firmware version that addresses this buffer overflow issue.
What systems are affected by CVE-2021-47854?
CVE-2021-47854 specifically affects DD-WRT version 45723 and potentially other versions if they utilize the same UPNP network discovery service.
How is CVE-2021-47854 exploited?
CVE-2021-47854 can be exploited by attackers sending crafted M-SEARCH packets with oversized UUID payloads.
What are the potential consequences of CVE-2021-47854?
The potential consequences of CVE-2021-47854 include unauthorized remote code execution which could compromise the security of the device.