DIRAS TAKE
Urgent — this CVE was added to CISA’s Known Exploited Vulnerabilities catalog with a rapid remediation deadline, so prioritize upgrading or applying mitigations immediately for internet-facing or UPnP-enabled DD-WRT devices.
What is CVE-2021-27137?
An unauthenticated remote attacker can trigger a stack-based buffer overflow in DD-WRT's UPnP SSDP handling (ssdp_msearch), leading to possible remote code execution (CVE-2021-27137). The flaw is caused by an unsafe strcpy in router/upnp/src/ssdp.c and is reachable via an M-SEARCH request when UPnP is enabled. Affected releases are DD-WRT builds before 45724; the attacker needs network access to an interface where UPnP is listening (UPnP is off by default and normally bound to internal interfaces).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of DD-WRT DD-WRT are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 45724.x | before 45724 | 45724 |
Is CVE-2021-27137 being exploited?
CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-07-21, and U.S. federal agencies were required to remediate it by 2026-07-24.
How to fix CVE-2021-27137
- Upgrade DD-WRT to build 45724 or later which contains the fix.
- If you cannot upgrade immediately, disable UPnP on affected DD-WRT devices.
- Restrict UPnP exposure to internal networks and block M-SEARCH from untrusted interfaces.
- Monitor device logs and network traffic for anomalous SSDP/M-SEARCH requests.
Frequently asked questions
Is CVE-2021-27137 being actively exploited?
CISA added CVE-2021-27137 to the Known Exploited Vulnerabilities catalog on 2026-07-21, and U.S. federal agencies were required to remediate it by 2026-07-24.
Which DD-WRT versions are affected by CVE-2021-27137?
DD-WRT builds before 45724 are affected; build 45724 contains the fix.
Is there a patch for CVE-2021-27137?
Yes — DD-WRT fixed the issue in build 45724; upgrade affected devices to that build or later.
Does CVE-2021-27137 require authentication?
No — the vulnerability can be triggered by an unauthenticated attacker via UPnP M-SEARCH requests when UPnP is enabled.
References
- nvd.nist.gov/vuln/detail/CVE-2021-27137
- cve.org/CVERecord?id=CVE-2021-27137
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137
- svn.dd-wrt.com/changeset/45724
- ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow
- securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html
- bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware
- fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo
- All DD-WRT CVEs on CVE Radar
- CVEs published in September 2026