← Back to Feed

DD-WRT Stack-Based Buffer Overflow Vulnerability

CVE-2021-27137

July 31, 2026 · CISA · Severity: CRITICAL

DD-WRT DD-WRT: DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. Vendor: DD-WRT Product: DD-WRT CISA Date Added: 2026-07-21 CVE: CVE-2021-27137 This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.

Key Takeaways

  • CVE-2021-27137 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
  • The flaw enables remote code execution, allowing attackers to run arbitrary commands on affected systems.
  • CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
  • DD-WRT DD-WRT: DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
☕ Buy a Coffee