
[CIVN-2026-0381] Buffer Overflow Vulnerability in DD-WRT Router Firmware
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Buffer Overflow Vulnerability in DD-WRT Router Firmware
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
DD-WRT Router Firmware versions prior to 45724
Overview
A vulnerability has been reported in DD-WRT Router Firmware, which could allow a remote attacker to send a request that would overflow an internal fixed buffer.
Target Audience:
All organizations and individuals using DD-WRT Router Firmware.
Risk Assessment:
Potential for unauthorized access to sensitive information, unauthorized execution of code, modification of router configuration or network traffic, and service unavailability.
Impact Assessment:
High risk of information disclosure, denial of service, and compromise of the affected router.
Description
DD-WRT is an open-source, Linux-based router firmware that replaces the default firmware to provide advanced networking features and greater control. It enhances router functionality with capabilities such as VPN support, QoS, VLANs, and improved wireless performance and security.
A vulnerability exists in DD-WRT Router Firmware due to an unsafe strcpy in the UPnP handling functionality.
Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. This exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default).
Solution
Apply appropriate updates as mentioned by the vendor:
https://dd-wrt.com/
https://nvd.nist.gov/vuln/detail/CVE-2021-2713
Vendor Information
DD-WRT
https://dd-wrt.com/
References
https://nvd.nist.gov/vuln/detail/CVE-2021-2713
CVE Name
CVE-2021-27137
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpqAp4ACgkQ3jCgcSdc
ys9gGQ/+M8ZqN15ax6ca7JPM4EZoEdizs9vwWX04brgnCcGDneX4ySftybQgO2HV
R80gV/fUMadWHX+JSDQtu0/WY0x39IZfjiHOLhV3FIHv80DVWI7wSdNlykgLl8VG
Fg/OH57QesQGBi1GaBxFqTgv7aqBFLN79o8EQodsXb5hACIEJxjk2roEwI/0ii0P
m6cqojFHCGCDnVnyK9HUZK105cgptRg1Zt3WQh6HHdibnfOCPH0CN2ISXiKVQkrP
9+9FCR+VvjgGP8BFJf3SeTl5ov0JCr5XgVoHtLH7/j7y/BStxnCeAN50r95Qr/v/
TtqTqlO5VpwbtFvDPJgk9U/HMmDVEvbNJl0owb9jTwUXmUxhnHgbmwv0lemGsVrf
+r8Lmwb36hORpHyl816BM2/SCienLjGLNr6SZqx81i08pUtvNUPn3O7O+/ASwJtM
va+vl1sW8o6uoq2mGuCsEd6G9XHuqZW+rtzYK16b+kAWoYwEaa3a+W+1KEfaoQc7
aXcl/VzSYl8P7ymlm3998OWrtCW7fj+PLjQ+C5AE8MpaNtJ8eLQ/3ktbzdS3iUSb
BDJcpjibZTw42yehKpYMPSc0Utgc7hQDfd+owLmfsPV3zbm+g0ZLC1Gdcy49kzOy
jvck/ml645yAR2n2WfEcxQKnQJUrD5oMwWhoLe6kGG3snmtXOQg=
=BzYs
—–END PGP SIGNATURE—–


