- Description
- An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- dd-wrt
CVSS 3.1
- Type
- Secondary
- Base score
- 8.1
- Impact score
- 5.9
- Exploitability score
- 2.2
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Data from CISA
- Vulnerability name
- DD-WRT Stack-Based Buffer Overflow Vulnerability
- Exploit added on
- Jul 21, 2026
- Exploit action due
- Jul 24, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- cve@mitre.org
- CWE-121
- Hype score
- Not currently trending
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに4件の脆弱性を追加。DD-WRTのCVE-2021-27137、LangflowのCVE-2026-0770、WordPressのCVE-2026-63030とCVE-2026-60137。対処期限は前3件が3日
@__kokumoto
21 Jul 2026
708 Impressions
0 Retweets
3 Likes
2 Bookmarks
1 Reply
0 Quotes
🚨 4 new CISA KEV adds today CVE-2021-27137, CVE-2026-0770, CVE-2026-63030, CVE-2026-60137 https://t.co/0StDFCzdCI #boarnet #cybersecurity #cisakev #cve #threatintelligence #malware
@boarnetio
21 Jul 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:dd-wrt:dd-wrt:*:*:*:*:*:*:*:*",
"matchCriteriaId": "69D9E341-F731-4BA7-9410-8EEBA216CBCA",
"versionEndExcluding": "45724",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]