DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • Wednesday, 22nd July, 2026
  • 10:04am

A security vulnerability has been identified in DD-WRT, a popular firmware used by many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error, that impacts the router's UPnP (Universal Plug and Play) feature, a tool designed to help devices on a local network automatically discover and connect to one another.

This issue can be exploited by an attacker who does not have any login credentials for the router. By sending specially crafted data to the router's UPnP service, an unauthenticated outsider could overflow the router's internal buffer, which may cause the router to crash, or even let the attacker run unauthorized code on the device.

If you use a DD-WRT-powered router for your internet connection, including to access or manage your web hosting services, this flaw may pose a risk to your device and your online accounts.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137

« Back