DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • Tuesday, 21st July, 2026
  • 22:02pm

A security vulnerability has been identified in DD-WRT, a popular firmware used for network routers and similar hardware. The flaw is a stack-based buffer overflow, a type of memory error that can cause unpredictable, unstable behavior in affected devices.

This issue impacts the UPnP (Universal Plug and Play) feature built into DD-WRT, a function designed to let devices on the same local network automatically discover and connect to each other for convenience. No login credentials are required for an attacker to attempt to exploit this flaw.

If successfully exploited, the vulnerability could allow an unauthenticated attacker to run unauthorized code on the affected DD-WRT device. This could let the attacker take control of the device, disrupt its operation, or use it to target other devices on the same network, including any hosted services or websites you operate behind that router.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137

« Back