AllCyberNews

CVE-2021-27137

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CVSS 8.1 high · DD-WRT DD-WRT · published 2026-07-16

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

Coverage 1 source

  1. 2026-07-21 CISA Cybersecurity Advisories high CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA added four new vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.

Mentioned with

CVE-2026-0770 CVE-2026-60137 CVE-2026-63030

Also covered