CVE-2021-27137
CVE-2021-27137 is a high-severity vulnerability in Dd-wrt with a CVSS 3.x base score of 8.1. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2026-07-21). The underlying weakness is classified as CWE-121.
Key facts
- Severity: High (CVSS 3.x base score 8.1)
- EPSS exploit prediction: 16% (97th percentile)
- Actively exploited: Yes — listed in CISA KEV (added 2026-07-21)
- Weakness: CWE-121
- Affected product: Dd-wrt
- Published:
- Last modified:
Description
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
Frequently asked questions
- What is CVE-2021-27137?
- An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
- How severe is CVE-2021-27137?
- CVE-2021-27137 has a CVSS 3.x base score of 8.1, rated high severity. It is exploitable over network with high attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
- Is CVE-2021-27137 being actively exploited?
- Yes. CVE-2021-27137 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2026-07-21, which means active exploitation has been confirmed. It should be prioritised for remediation.
- What products are affected by CVE-2021-27137?
- CVE-2021-27137 affects Dd-wrt. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-27137?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
- When was CVE-2021-27137 published?
- CVE-2021-27137 was published on 2026-07-16 and last updated on 2026-07-22.
References
- https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html
- https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
- https://svn.dd-wrt.com/changeset/45724
- https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/
- https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137
Affected products (1)
- cpe:2.3:o:dd-wrt:dd-wrt:*:*:*:*:*:*:*:*
More vulnerabilities in Dd-wrt
- CVE-2022-27631 — Critical (CVSS 9.8): A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599.…
- CVE-2020-13976 — High (CVSS 8.8): An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary…
- CVE-2012-6297 — High (CVSS 8.8): Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values…
- CVE-2009-2765 — High (CVSS 8.3): httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers…
- CVE-2009-2766 — High (CVSS 7.5): httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs…
- CVE-2008-6975 — Medium (CVSS 6.8): Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to…
Other CWE-121 (Stack-based Buffer Overflow) vulnerabilities
- CVE-2026-12848 — Critical (CVSS 10.0): GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and…
- CVE-2026-12847 — Critical (CVSS 10.0): GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and…
- CVE-2026-12846 — Critical (CVSS 10.0): GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and…
- CVE-2026-12485 — Critical (CVSS 10.0): GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and…
- CVE-2026-37541 — Critical (CVSS 10.0): Buffer overflow vulnerability in Open Vehicle Monitoring System 3 (OVMS3) 3.3.005. In canformat_gvret.cpp, the length…
- CVE-2026-42996 — Critical (CVSS 10.0): JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of…
Browse all CWE-121 (Stack-based Buffer Overflow) vulnerabilities →