Vulnerability record · CVE-2021-27137 · published 16 July 2026
CVE-2021-27137: DD-WRT UPnP M-SEARCH stack buffer overflow
Dd Wrt · Dd Wrt
DD-WRT before 45724 contains an unsafe strcpy in the UPnP SSDP handling code (ssdp_msearch), reachable via an M-SEARCH request, that overflows a fixed internal stack buffer. The flaw is remotely exploitable without authentication, but only when the user has enabled UPnP, which is off by default and normally listens only on internal interfaces. It matters because it has been added to CISA KEV and is being used by the c0xmo botnet to spread across routers.
Description
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and is in CISA KEV with documented botnet exploitation, though default-off UPnP and internal-only listening reduce exposure.
What it is
DD-WRT before 45724 contains an unsafe strcpy in the UPnP SSDP handling code (ssdp_msearch), reachable via an M-SEARCH request, that overflows a fixed internal stack buffer. The flaw is remotely exploitable without authentication, but only when the user has enabled UPnP, which is off by default and normally listens only on internal interfaces. It matters because it has been added to CISA KEV and is being used by the c0xmo botnet to spread across routers.
Impact
A successful overflow can corrupt stack memory and allow an unauthenticated remote attacker to execute code or crash the device, giving control of the router. In the observed campaign the flaw is used for botnet propagation, including killing rival malware on infected devices.
Attack surface
Reached over the network by sending a crafted M-SEARCH request to the UPnP/SSDP service; no authentication or user interaction is required. Exposure depends on UPnP being enabled and the service being reachable, since it is off by default and listens only on internal interfaces by default.
Exploitation
Listed in CISA KEV (added 2026-07-21) and referenced by multiple exploit-tagged advisories and threat reports describing active c0xmo botnet use. EPSS 30-day probability is about 4.0 percent (percentile ~90), so mass exploitation is not indicated but targeted abuse is documented.
What to do
- Upgrade DD-WRT to version 45724 or later, which contains the patch (changeset 45724).
- If patching is not immediately possible, disable UPnP on DD-WRT devices and restrict the SSDP/UPnP service to trusted internal networks only.
- Block or filter inbound SSDP/UPnP (UDP 1900) traffic at network boundaries and do not expose router management or UPnP services to the internet.
- Follow CISA BOD 26-04 guidance for affected assets, including evaluating internet exposure and discontinuing use if mitigations are unavailable.
- Inventory DD-WRT devices and confirm UPnP state, since the flaw is only reachable when UPnP is enabled.
Detection
- Monitor for anomalous or oversized M-SEARCH requests to UDP 1900 targeting DD-WRT devices.
- Watch for router crashes, reboots, or unexpected process restarts correlated with UPnP/SSDP traffic.
- Hunt for c0xmo botnet indicators and outbound connections from routers to known C2 or scanning infrastructure.
- Audit DD-WRT device configurations for enabled UPnP and external reachability of the SSDP service.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-27137 to the Known Exploited Vulnerabilities catalog on 21 July 2026 as "DD-WRT Stack-Based Buffer Overflow Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 24 July 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html | ExploitThird Party Advisory |
| https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/ | ExploitThird Party Advisory |
| https://svn.dd-wrt.com/changeset/45724 | Patch |
| https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/ | ExploitThird Party Advisory |
| https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo | Exploit |
| https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137 | US Government Resource |
Track CVE-2021-27137 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-27137), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.