Fixing and finding
Jump to remediation plan
CVE ID

CVE-2021-27137

Published 2026-07-16
Updated 2 months ago
Vendor/s
DD-WRT
Product/s
DD-WRT
Version/s
* > 45724
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
8.1
/ 10
High
Severity Details
Base score
8.1 High
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2021-27137 is a high-severity buffer overflow in DD-WRT's UPnP service. It is actively exploited and requires immediate patching to build 45724.

CPE

DD-WRT logo
DD-WRT
Product Version Start Version End (excl.) Status
dd-wrt * 45724 vulnerable

Related weakness (CWE)

CWE-121

Remediation plan

1

Apply official patches

Install the latest DD-WRT firmware update immediately. The vulnerability was addressed in changeset 45724; ensure your router is running this build or a more recent version provided by the vendor.

2

Update affected systems

Identify all hardware assets running DD-WRT firmware versions prior to build 45724. Perform a manual firmware flash across all affected devices to eliminate the vulnerable ssdp.c component.

3

Restrict access

Disable UPnP (Universal Plug and Play) within the DD-WRT web interface if the functionality is not business-critical. If UPnP must remain active, ensure it is restricted to trusted internal interfaces only.

4

Monitor for exploitation

Audit internal network traffic for malformed or excessively long SSDP M-SEARCH packets. Monitor router system logs for unexpected service restarts or segmentation faults associated with the ssdp process.

Detection Guidance

"To detect potential exploitation of CVE-2021-27137, monitor internal network traffic for anomalous SSDP M-SEARCH requests, specifically those containing unusually long string values that could trigger a buffer overflow. Use Intrusion Detection Systems (IDS) to flag malformed UPnP headers. Additionally, review DD-WRT system logs for segmentation faults or service restarts associated with ssdp.c, which often indicate an exploitation attempt."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management