A security flaw has been found in DD-WRT, a widely used firmware for routers and other network hardware that many people use to support their websites and online services. This is a stack-based buffer overflow vulnerability, a type of programming error that can cause systems to operate in unexpected, unsafe ways. The issue exists in the part of DD-WRT that runs UPnP, a feature that lets devices on the same local network automatically discover and connect to each other for convenience. An attacker does not need any login credentials or prior access to exploit this vulnerability. If triggered, the flaw lets an attacker run unauthorized code on the affected DD-WRT device. This could allow them to take control of the device, disrupt its normal operation, or use it as a foothold to attack other devices connected to the same network.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137