[KEV] CVE-2021-27137 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2021-27137 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2021-27137 is a stack-based buffer overflow in the UPnP functionality of DD-WRT firmware that can be reached by an unauthenticated attacker.
Technical Detail
The vulnerability occurs when DD-WRT processes UPnP input using an internal buffer without sufficient bounds checking. An attacker can send crafted UPnP requests to overflow the buffer and potentially execute arbitrary code on the affected device. The available data does not identify affected DD-WRT versions or the execution context of successful code execution.
Exploitation Status
Exploit maturity is operational, meaning working exploitation methods are available and can be used in real-world attack activity. CISA has confirmed active exploitation in the wild. The vulnerability was added to the CISA Known Exploited Vulnerabilities Catalog on July 21, 2026.
Who Is Targeting This
No specific threat actor attribution at this time.
What To Do
Prioritize remediation for internet-exposed and externally reachable DD-WRT devices. Apply an updated DD-WRT firmware release that addresses CVE-2021-27137 when available from the vendor or project maintainer. Until patched, disable UPnP where operationally feasible, restrict access to router management and UPnP services from untrusted networks, and ensure UPnP is not exposed to the public internet. Review router and network logs for unexpected UPnP requests, configuration changes, new administrative access, or unexplained outbound traffic. As this vulnerability is KEV-listed, CISA binding directive requirements apply: patch by the applicable CISA KEV deadline or apply mitigations; the supplied record does not include a specific remediation due date.