EXPOSURES › CVE-2021-27137
CVE-2021-27137
HIGH ⌖ ON CISA KEV · EXPLOITEDDD-WRT exposed to active exploitation for years without patching a critical buffer overflow flaw
DD-WRT, a widely-used router firmware, remained unpatched for an exploitable buffer overflow vulnerability for over five years, enabling unauthenticated attackers to execute arbitrary code. This lapse in security maintenance directly exposed users to potential remote code execution attacks, highlighting the vendor's negligence in addressing a known and actively exploited vulnerability.
Shame score — Negligence in maintaining security for a widely-used product despite knowing of active exploitation.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.