DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • Tuesday, 21st July, 2026
  • 16:02pm

A security vulnerability has been identified in DD-WRT, a popular custom firmware installed on many internet routers that customers use to connect their local devices to hosted websites and online services. The flaw takes the form of a stack-based buffer overflow, a type of software memory error that can cause unexpected, harmful behavior.

This vulnerability specifically impacts the router's built-in UPnP (Universal Plug and Play) feature, a tool that lets devices on your local network automatically discover and connect to each other for common tasks like remote access, media streaming, and device sharing.

The flaw can be exploited by an attacker with no special login credentials for the router. If targeted, an attacker could trigger the buffer overflow to run unauthorized code on the affected device. This may allow them to intercept data traveling to and from your network, disrupt your connection to your hosted services, or take control of other devices connected to the router.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137

« Back