CVSS v3
8.1
HIGH
EPSS Score
5.4 %
exploit probability
CISA KEV
Yes
known exploited
Exploitation
—
SSVC status
Description
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
CISA Known Exploited Vulnerability
- Date Added
- 2026-07-21
- Patch Due Date
- 2026-07-24
- Ransomware Use
- Unknown
Technical details
- CVSS v3 Vector
- 3.1
- Published
- 2026-07-16
- Last Modified
- 2026-07-17
Frequently asked questions
What is CVE-2021-27137?
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
Is CVE-2021-27137 actively exploited?
Yes. CVE-2021-27137 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 2026-07-24.
What is the CVSS score for CVE-2021-27137?
CVE-2021-27137 has a CVSS v3 base score of 8.1 (HIGH severity), with vector string 3.1.
Is CVE-2021-27137 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2021 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).