๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Vulnerability
Summary
DD-WRT contains a stack-based buffer overflow vulnerability (a flaw where too much data gets written into a small memory area, corrupting nearby data) in its UPnP component (a protocol that lets devices discover and communicate with each other) that could allow an attacker without login credentials to execute malicious code on affected systems. This vulnerability is currently being exploited by attackers in the wild.
Solution / Mitigation
Apply mitigations according to vendor instructions while following CISA's BOD 26-04 guidance for prioritizing security updates based on risk. If mitigations are unavailable, discontinue use of the product. Check with DD-WRT vendors for patching status and ensure compliance with BOD 26-04 patching guidelines based on each asset's exposure to the internet. The due date for remediation is 2026-07-24.
Vulnerability Details
EPSS: 5.4%
Yes
๐ฅ Actively Exploited
July 20, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2021-27137
First tracked: July 21, 2026 at 02:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%