A security vulnerability has been identified in DD-WRT, a popular firmware that runs on many home and small business Wi-Fi routers. The flaw is a buffer overflow bug in the router's Universal Plug and Play (UPnP) feature, a tool that lets devices on your local network automatically discover and connect to each other for uses like streaming media or sharing files. An attacker does not need any login credentials for your router to exploit this issue: they can send specially crafted data to the UPnP feature to trigger the bug. If successfully exploited, the bug could allow an attacker to run unauthorized code on your router. This could let them modify your router's settings, monitor activity on your network, or target any websites or online services you host that are accessible through the affected router.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137