Vulnerabilities
Vulnerable Software
Dd-Wrt:  >> Dd-Wrt  >> 32270  Security Vulnerabilities
CVE-2021-27137
Known exploited
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
CVSS Score
8.1
EPSS Score
0.054
Published
2026-07-16
A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
CVSS Score
5.3
EPSS Score
0.01
Published
2022-08-05


Contact Us

Shodan ® - All rights reserved