A security vulnerability has been identified in DD-WRT, a popular open-source firmware used for many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error that can cause a program to behave unexpectedly or run unauthorized instructions.
The error exists in DD-WRT’s built-in UPnP (Universal Plug and Play) feature, a tool that lets devices on your local network automatically detect and connect to each other without manual configuration. An attacker does not need any existing login credentials or access to your network to exploit this flaw: they can trigger the buffer overflow to run unauthorized code on your router.
If you use a router running DD-WRT firmware to connect your hosted websites, servers, or other online services to the internet, a successful exploit could let an attacker take control of your router. This could disrupt your hosted services, allow unauthorized access to devices connected to your local network, or let an attacker use your network connection for malicious activity.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2021-27137