[KEV] CVE-2021-27137 -- CVSS 0.0 Vulnerability Briefing
[KEV] CVE-2021-27137 | CVSS 0.0 (Low) | Exploit: Operational
What Is It
CVE-2021-27137 is a stack-based buffer overflow vulnerability in DD-WRT firmware, specifically within the UPnP service component, exploitable by unauthenticated remote attackers.
Technical Detail
The flaw exists in DD-WRT's UPnP implementation, where an attacker can send a crafted request that overflows an internal stack buffer without requiring any authentication. Successful exploitation of this overflow can allow an attacker to overwrite the stack frame and redirect execution, resulting in unauthenticated remote code execution (RCE) on the affected device. Because UPnP is commonly exposed on LAN-facing interfaces and in some configurations on WAN-facing interfaces, the attack surface may extend beyond the local network depending on device configuration.
Exploitation Status
CISA has confirmed active exploitation in the wild, with this vulnerability added to the Known Exploited Vulnerabilities catalog on July 21, 2026. The exploit maturity is rated Operational, meaning functional exploit code capable of achieving reliable code execution exists and is being used in real-world attacks, not merely as a proof-of-concept demonstration.
Who Is Targeting This
No specific threat actor attribution at this time. Neither confirmed nor reported threat actor associations are available in current intelligence data. Given the device class affected (consumer and small business routers running DD-WRT) and the confirmed exploitation status, opportunistic actors targeting network edge devices are a reasonable operational assumption, but no named groups have been attributed.
What To Do
Per CISA's Known Exploited Vulnerabilities directive, organizations must patch this vulnerability or apply mitigations by the required remediation date following the July 21, 2026 KEV listing. Administrators running DD-WRT should update to the latest available firmware build immediately, as DD-WRT releases are build-dated rather than versioned in a traditional sense. As an interim measure, disable UPnP on all DD-WRT devices where it is not strictly required, particularly on any interface exposed to untrusted networks. Verify that WAN-side UPnP exposure is blocked at the network perimeter. Review firewall and router logs for anomalous UPnP traffic or unexpected outbound connections from affected devices as a detection signal for potential compromise.