CVE-2021-27137
Exploited in the wild. In CISA KEV since 2026‑07‑21. A vendor fix is available.
What to do
The vendor has published a fix. Version details are below where the sources state them.
What it is
From the CVE record
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
In plain language
No plain-language summary for this CVE yet.
Exploitation
Where each signal puts this CVE on the scale from published to confirmed exploited.
- CISA KEV
Listed as exploited in the wild since 2026-07-21.
US federal agencies must remediate by 2026-07-24.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
- Public exploits
No public exploit or proof of concept found in the sources we track.
- EPSS
4.0% chance of exploitation activity in the next 30 days, which ranks it in the 90th percentile of scored CVEs.
Exploit Prediction Scoring System, FIRST.org. A probability, not a confirmation.
Lifecycle
16 events over 39 days, from the signal feeds we watch.
- EPSS band changemoderate → 0epss band change
- Analysis publishedThe Router Bug DD-WRT Patched in 2021 Just Became a Botnet's Front Door
- EPSS band changelow → moderate
- EPSS band change0 → moderateepss band change, patch available, record updated
- Added to CISA KEVpatch available, record updated
- Record updated
Affected products
And 1 more affected product. See all after sign-in
Technical detail
CVSS 3.1 vector
Open in the CVSS calculatorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored 8.1 by NVD.
How it is reached
- Attack Vector NetworkExploitable remotely over the network without any special conditions
- Attack Complexity HighRequires specific conditions like a race condition or non-default configuration
- Privileges Required NoneNo authentication required — anyone can exploit this
- User Interaction NoneNo user interaction needed — fully automated exploitation
Scope
- Scope UnchangedImpact is limited to the vulnerable component itself
Impact if exploited
- Confidentiality HighTotal information disclosure — all data in the component is compromised
- Integrity HighTotal loss of integrity — attacker can modify any data in the component
- Availability HighTotal denial of service — the component is completely unavailable
Weaknesses
ATT&CK techniques
Mapped from the weaknesses above (CWE to ATT&CK), not observed in attacks.
- Privilege EscalationT1068Exploitation for Privilege Escalationhigh confidence
Sources
References in the record
- svn.dd-wrt.com/changeset/45724
- ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/
- securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html
And 3 more references. See all after sign-in
In the news
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
- COXMO Botnet Variant: New Advanced Threat Exploits Router Firmware
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
- Ботнет C0XMO атакует маршрутизаторы с прошивкой DD-WRT
- C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
Watch the software you run.
My Stack ranks new CVEs for your products by real-world exploitation, so the next exploited one reaches you without reading every advisory.
We'll flag the next CVE, public exploit or patch for DD-WRT, not every advisory. This one: actively exploited.
A free account adds
- The full version matrix and every affected product
- Exploit links, proofs of concept and Metasploit modules
- Email alerts for the products you watch
- The same data over REST API, MCP and CLI