DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • Friday, 24th July, 2026
  • 04:03am

A security flaw has been identified in DD-WRT, a widely used custom firmware for home and small business network routers. The issue is a stack-based buffer overflow, a type of software bug that can cause a device to crash or behave in unintended ways.

The vulnerability targets the router’s UPnP feature, a common tool that lets devices on your local network automatically discover and connect to each other. An unauthenticated attacker—someone who does not need login credentials for your router—could exploit this flaw by sending a specially designed request to the UPnP function, which could trigger the bug to run unauthorized, malicious code on the affected router.

If you use DD-WRT on your network to connect web hosting servers or other hosting-related devices to the internet, this flaw could put those connected systems at risk of disruption or unauthorized access.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137

« Back