[CIVN-2026-0381] Buffer Overflow Vulnerability in DD-WRT Router Firmware

By Published On: July 29, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Buffer Overflow Vulnerability in DD-WRT Router Firmware


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


DD-WRT Router Firmware versions prior to 45724 

Overview


A vulnerability has been reported in DD-WRT Router Firmware, which could allow a remote attacker to send a request that would overflow an internal fixed buffer.


Target Audience:

All organizations and individuals using DD-WRT Router Firmware.

 

Risk Assessment:

Potential for unauthorized access to sensitive information, unauthorized execution of code, modification of router configuration or network traffic, and service unavailability.


Impact Assessment:

High risk of information disclosure, denial of service, and compromise of the affected router.


Description


DD-WRT is an open-source, Linux-based router firmware that replaces the default firmware to provide advanced networking features and greater control. It enhances router functionality with capabilities such as VPN support, QoS, VLANs, and improved wireless performance and security.


A vulnerability exists in DD-WRT Router Firmware due to an unsafe strcpy in the UPnP handling functionality.


Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. This exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default).


Solution


Apply appropriate updates as mentioned by the vendor:

https://dd-wrt.com/


https://nvd.nist.gov/vuln/detail/CVE-2021-2713



Vendor Information


DD-WRT

https://dd-wrt.com/


References


 

https://nvd.nist.gov/vuln/detail/CVE-2021-2713


CVE Name

CVE-2021-27137




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpqAp4ACgkQ3jCgcSdc

ys9gGQ/+M8ZqN15ax6ca7JPM4EZoEdizs9vwWX04brgnCcGDneX4ySftybQgO2HV

R80gV/fUMadWHX+JSDQtu0/WY0x39IZfjiHOLhV3FIHv80DVWI7wSdNlykgLl8VG

Fg/OH57QesQGBi1GaBxFqTgv7aqBFLN79o8EQodsXb5hACIEJxjk2roEwI/0ii0P

m6cqojFHCGCDnVnyK9HUZK105cgptRg1Zt3WQh6HHdibnfOCPH0CN2ISXiKVQkrP

9+9FCR+VvjgGP8BFJf3SeTl5ov0JCr5XgVoHtLH7/j7y/BStxnCeAN50r95Qr/v/

TtqTqlO5VpwbtFvDPJgk9U/HMmDVEvbNJl0owb9jTwUXmUxhnHgbmwv0lemGsVrf

+r8Lmwb36hORpHyl816BM2/SCienLjGLNr6SZqx81i08pUtvNUPn3O7O+/ASwJtM

va+vl1sW8o6uoq2mGuCsEd6G9XHuqZW+rtzYK16b+kAWoYwEaa3a+W+1KEfaoQc7

aXcl/VzSYl8P7ymlm3998OWrtCW7fj+PLjQ+C5AE8MpaNtJ8eLQ/3ktbzdS3iUSb

BDJcpjibZTw42yehKpYMPSc0Utgc7hQDfd+owLmfsPV3zbm+g0ZLC1Gdcy49kzOy

jvck/ml645yAR2n2WfEcxQKnQJUrD5oMwWhoLe6kGG3snmtXOQg=

=BzYs

—–END PGP SIGNATURE—–

Share this article