PT-2026-46055 · Dd-Wrt · Dd-Wrt Upnp

CVE-2021-27137

·

Published

2026-06-03

·

Updated

2026-07-22

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DD-WRT versions prior to 45724
Description An unsafe strcpy function in the UPnP handling functionality within router/upnp/src/ssdp.c allows an unauthenticated remote attacker to overflow an internal fixed buffer. This issue is triggered via an M-SEARCH request processed by the ssdp msearch() function, specifically when large ST:uuid values are handled incorrectly over UDP port 1900. Exploitation requires the user to have UPnP enabled. This flaw has been exploited by the C0xmo botnet, a Gafgyt variant, to compromise devices across multiple architectures including ARM, MIPS, PowerPC, SuperH, MC68000, Intel 80386, and AMD64. A confirmed incident involved a Japanese technology firm where the attack originated from an IP address in Germany.
Recommendations Update DD-WRT to version 45724 or later. Disable UPnP on port 1900.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-27137

Affected Products

Dd-Wrt Upnp