← Back to Feed
DD-WRT Stack-Based Buffer Overflow Vulnerability
CVE-2021-27137
July 31, 2026 · CISA · Severity: CRITICAL
DD-WRT DD-WRT: DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Vendor: DD-WRT
Product: DD-WRT
CISA Date Added: 2026-07-21
CVE: CVE-2021-27137
This vulnerability is actively exploited in the wild according to CISA Known Exploited Vulnerabilities catalog.
Key Takeaways
- CVE-2021-27137 is actively exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities catalog.
- The flaw enables remote code execution, allowing attackers to run arbitrary commands on affected systems.
- CISA BOD 26-04 requires remediation within the specified due date — apply vendor mitigations promptly.
- DD-WRT DD-WRT: DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.