PT-2026-46055 · Dd-Wrt · Dd-Wrt Upnp
CVE-2021-27137
·
Published
2026-06-03
·
Updated
2026-07-22
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DD-WRT versions prior to 45724
Description
An unsafe
strcpy function in the UPnP handling functionality within router/upnp/src/ssdp.c allows an unauthenticated remote attacker to overflow an internal fixed buffer. This issue is triggered via an M-SEARCH request processed by the ssdp msearch() function, specifically when large ST:uuid values are handled incorrectly over UDP port 1900. Exploitation requires the user to have UPnP enabled. This flaw has been exploited by the C0xmo botnet, a Gafgyt variant, to compromise devices across multiple architectures including ARM, MIPS, PowerPC, SuperH, MC68000, Intel 80386, and AMD64. A confirmed incident involved a Japanese technology firm where the attack originated from an IP address in Germany.Recommendations
Update DD-WRT to version 45724 or later.
Disable UPnP on port 1900.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dd-Wrt Upnp