DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • Thursday, 23rd July, 2026
  • 22:03pm

We’re reaching out to share details about a confirmed security vulnerability found in DD-WRT, a popular open-source firmware used for many routers that website and small business owners often use to manage their hosting and office network connections. The flaw is a type of coding error called a stack-based buffer overflow, which impacts the internal processing buffer for DD-WRT’s built-in UPnP (Universal Plug and Play) feature, a tool designed to automatically simplify connecting new devices to your network without manual configuration. An attacker does not need any account credentials or prior access to your network to exploit this flaw, and a successful attack could allow the attacker to run unauthorized, malicious code on the affected router.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137

« Back