A security vulnerability has been identified in DD-WRT, a popular custom firmware used by many people to run their home or small office internet routers. This flaw is a stack-based buffer overflow, a type of software bug that happens when a program receives more input data than the small, fixed storage space it reserves for that data is designed to hold.
This specific bug affects the UPnP (Universal Plug and Play) feature built into DD-WRT, a tool that lets devices on your network automatically find and connect to each other and the internet without manual setup. An attacker does not need any login credentials or prior access to your router to exploit this flaw.
If successfully triggered, the vulnerability could allow an attacker to run their own unauthorized code on your router. This may let them take control of your router, monitor all internet traffic passing through your network, or use your connection to carry out attacks on other people or systems.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137