• CISA KEV
  • EXPLOITED
  • PATCH AVAILABLE

CVE-2021-27137: pre-auth remote code execution in DD-WRT DD-WRT

An unauthenticated remote attacker can trigger a stack-based buffer overflow in DD-WRT's UPnP SSDP handling (ssdp_msearch), leading to possible remote code execution (CVE-2021-27137). The flaw is caused by an unsafe strcpy in router/upnp/src/ssdp.c and is reachable via an M-SEARCH request when UPnP is enabled. Affected releases are DD-WRT builds before 45724; the attacker needs network access to an interface where UPnP is listening (UPnP is off by default and normally bound to internal interfaces).

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
8.1HIGH
EPSS
0.03995
CWE
CWE-121
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize upgrading or applying mitigations immediately for internet-facing or UPnP-enabled DD-WRT devices.

What is CVE-2021-27137?

An unauthenticated remote attacker can trigger a stack-based buffer overflow in DD-WRT's UPnP SSDP handling (ssdp_msearch), leading to possible remote code execution (CVE-2021-27137). The flaw is caused by an unsafe strcpy in router/upnp/src/ssdp.c and is reachable via an M-SEARCH request when UPnP is enabled. Affected releases are DD-WRT builds before 45724; the attacker needs network access to an interface where UPnP is listening (UPnP is off by default and normally bound to internal interfaces).

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of DD-WRT DD-WRT are affected?

BRANCHAFFECTEDFIXED
45724.xbefore 4572445724

Is CVE-2021-27137 being exploited?

CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-21, and U.S. federal agencies were required to remediate it by 2026-07-24.

How to fix CVE-2021-27137

  1. Upgrade DD-WRT to build 45724 or later which contains the fix.
  2. If you cannot upgrade immediately, disable UPnP on affected DD-WRT devices.
  3. Restrict UPnP exposure to internal networks and block M-SEARCH from untrusted interfaces.
  4. Monitor device logs and network traffic for anomalous SSDP/M-SEARCH requests.

Frequently asked questions

Is CVE-2021-27137 being actively exploited?

CISA added CVE-2021-27137 to the Known Exploited Vulnerabilities catalog on 2026-07-21, and U.S. federal agencies were required to remediate it by 2026-07-24.

Which DD-WRT versions are affected by CVE-2021-27137?

DD-WRT builds before 45724 are affected; build 45724 contains the fix.

Is there a patch for CVE-2021-27137?

Yes — DD-WRT fixed the issue in build 45724; upgrade affected devices to that build or later.

Does CVE-2021-27137 require authentication?

No — the vulnerability can be triggered by an unauthenticated attacker via UPnP M-SEARCH requests when UPnP is enabled.

References