← Vulnerability feed

Vulnerability record · CVE-2021-27137 · published 16 July 2026

CVE-2021-27137: DD-WRT UPnP M-SEARCH stack buffer overflow

Dd Wrt · Dd Wrt

DD-WRT before 45724 contains an unsafe strcpy in the UPnP SSDP handling code (ssdp_msearch), reachable via an M-SEARCH request, that overflows a fixed internal stack buffer. The flaw is remotely exploitable without authentication, but only when the user has enabled UPnP, which is off by default and normally listens only on internal interfaces. It matters because it has been added to CISA KEV and is being used by the c0xmo botnet to spread across routers.

8.1 CVSS 3.1 High CISA KEV since 21 Jul 2026 EPSS 4.0% · top 9.8% CWE-121 · Stack-based buffer overflow
8.1CVSS 3.1 base score
4.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 5 tagged exploit
22 Jul 2026Last modified by NVD

Description

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is remotely exploitable without authentication and is in CISA KEV with documented botnet exploitation, though default-off UPnP and internal-only listening reduce exposure.

What it is

DD-WRT before 45724 contains an unsafe strcpy in the UPnP SSDP handling code (ssdp_msearch), reachable via an M-SEARCH request, that overflows a fixed internal stack buffer. The flaw is remotely exploitable without authentication, but only when the user has enabled UPnP, which is off by default and normally listens only on internal interfaces. It matters because it has been added to CISA KEV and is being used by the c0xmo botnet to spread across routers.

Impact

A successful overflow can corrupt stack memory and allow an unauthenticated remote attacker to execute code or crash the device, giving control of the router. In the observed campaign the flaw is used for botnet propagation, including killing rival malware on infected devices.

Attack surface

Reached over the network by sending a crafted M-SEARCH request to the UPnP/SSDP service; no authentication or user interaction is required. Exposure depends on UPnP being enabled and the service being reachable, since it is off by default and listens only on internal interfaces by default.

Exploitation

Listed in CISA KEV (added 2026-07-21) and referenced by multiple exploit-tagged advisories and threat reports describing active c0xmo botnet use. EPSS 30-day probability is about 4.0 percent (percentile ~90), so mass exploitation is not indicated but targeted abuse is documented.

What to do

  • Upgrade DD-WRT to version 45724 or later, which contains the patch (changeset 45724).
  • If patching is not immediately possible, disable UPnP on DD-WRT devices and restrict the SSDP/UPnP service to trusted internal networks only.
  • Block or filter inbound SSDP/UPnP (UDP 1900) traffic at network boundaries and do not expose router management or UPnP services to the internet.
  • Follow CISA BOD 26-04 guidance for affected assets, including evaluating internet exposure and discontinuing use if mitigations are unavailable.
  • Inventory DD-WRT devices and confirm UPnP state, since the flaw is only reachable when UPnP is enabled.

Detection

  • Monitor for anomalous or oversized M-SEARCH requests to UDP 1900 targeting DD-WRT devices.
  • Watch for router crashes, reboots, or unexpected process restarts correlated with UPnP/SSDP traffic.
  • Hunt for c0xmo botnet indicators and outbound connections from routers to known C2 or scanning infrastructure.
  • Audit DD-WRT device configurations for enabled UPnP and external reachability of the SSDP service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-27137 to the Known Exploited Vulnerabilities catalog on 21 July 2026 as "DD-WRT Stack-Based Buffer Overflow Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 24 July 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-27137 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-27631Dd-wrt out-of-bounds write vulnerabilityA memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP requ…EPSS 1.1%8.8CVE-2020-13976Dd-wrt os command injection vulnerabilityAn issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters i…EPSS 1.8%8.8CVE-2012-6297Dd-wrt cross-site request forgery vulnerabilityCommand Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, whic…EPSS 1.7%8.3CVE-2009-2765DD-WRT management GUI httpd command injection via cgi-bin URIThe httpd.c component of the DD-WRT management GUI fails to validate input in requests to cgi-bin/ URIs, allowing shell metacharacters to be passed i…EPSS 83%analysed7.5CVE-2009-2766Dd-wrt permissions and access controls vulnerabilityhttpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remo…EPSS 5.1%6.8CVE-2008-6974Dd-wrt cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authenticat…EPSS 1.5%6.8CVE-2008-6975Dd-wrt cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of admin…EPSS 1.3%8.8CVE-2026-7273Zyxel gs1900-8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.90(ABTQ.1)C0 could allow a LAN-base…KEVEPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2021-27137), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.