CVE-2021-27137
exploitation · critical · Evidence score 90
- Vendor
- DD-WRT
- Affected software
- DD-WRT DD-WRT
- Exploitation signal
- Listed in CISA Known Exploited Vulnerabilities
- EPSS
- 0.16488
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.
Provenance
CISA Known Exploited Vulnerabilities
21 July 2026, 10:00 AM AEST