[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2021-27137":6},{"stargazers_count":4,"fetched_at":5},7,"2026-08-22T20:44:10.849Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":20,"aliases":45,"duplicate_of":9,"upstream":46,"downstream":47,"duplicates":48,"related":49,"reserved_at":9,"published_at":50,"modified_at":51,"state":52,"summary":53,"references_raw":63,"kevs":90,"epss":100,"epss_history":103,"metrics":208,"affected":216},"CVE-2021-27137","An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-121","Stack-based Buffer Overflow","A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).","weakness","Draft","Variant","High",[],[21,30,35,40],{"_key":22,"name":23,"source":24,"url":25,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":29,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_DFAF56AECB334FFA","Exploit Reference (ssd-disclosure.com)","reference","https://ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/","unknown",0.2,false,[],{"_key":31,"name":32,"source":24,"url":33,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":34,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_60D03F20E5ABF2F5","Exploit Reference (securityaffairs.com)","https://securityaffairs.com/193290/uncategorized/iot-botnet-c0xmo-adds-competitor-killing-capability.html",[],{"_key":36,"name":37,"source":24,"url":38,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":39,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_AF428B1714ADC784","Exploit Reference (bleepingcomputer.com)","https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/",[],{"_key":41,"name":42,"source":24,"url":43,"maturity":26,"reliability_score":27,"verified":28,"type":9,"platforms":44,"requires_auth":9,"exploitdb":9,"metasploit":9},"REF_C005A7B23CAACA40","Exploit Reference (fortinet.com)","https://www.fortinet.com/blog/threat-research/inside-cross-platform-propagation-of-new-gafgyt-variant-c0xmo",[],[],[],[],[],[],"2026-07-16T00:00:00.000Z","2026-07-22T03:55:45.793Z","Analyzed",{"cisa_kev":54,"cisa_ransomware":28,"cisa_vendor":55,"epss_severity":56,"epss_score":57,"severity":58,"severity_score":59,"severity_version":60,"severity_source":61,"severity_vector":62,"severity_status":52},true,"DD-WRT","medium",0.16488,"high",8.1,"v3.1","cve.org","CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",[64,70,75,78,81,84],{"url":65,"sources":66,"tags":68},"https://svn.dd-wrt.com/changeset/45724",[61,67],"nvd",[69],"Patch",{"url":25,"sources":71,"tags":72},[61,67],[73,74],"Exploit","Third Party Advisory",{"url":33,"sources":76,"tags":77},[61,67],[73,74],{"url":38,"sources":79,"tags":80},[61,67],[73,74],{"url":43,"sources":82,"tags":83},[61,67],[73],{"url":85,"sources":86,"tags":87},"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-27137",[61,67],[88,89],"Government Resource","US Government Resource",[91],{"source":92,"vendor":55,"product":55,"date_added":93,"vulnerability_name":94,"short_description":95,"required_action":96,"due_date":97,"known_ransomware_campaign_use":98,"notes":99,"exploitation_type":9},"cisa","2026-07-21","DD-WRT Stack-Based Buffer Overflow Vulnerability","DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.","Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","2026-07-24","Unknown","This vulnerability affects a common open-source component, third-party library, proprietary implementation, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://svn.dd-wrt.com/changeset/45724 ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2021-27137",{"date":101,"score":57,"percentile":102},"2026-08-22",0.96741,[104,108,111,114,117,119,123,126,128,131,134,136,139,142,145,148,151,153,155,158,161,164,167,170,172,174,177,180,183,186,189,192,195,198,201,204,207],{"date":105,"score":106,"percentile":107},"2026-07-17",0.05447,0.91835,{"date":109,"score":106,"percentile":110},"2026-07-18",0.91838,{"date":112,"score":106,"percentile":113},"2026-07-19",0.91841,{"date":115,"score":106,"percentile":116},"2026-07-20",0.91854,{"date":93,"score":106,"percentile":118},0.91861,{"date":120,"score":121,"percentile":122},"2026-07-22",0.10809,0.95377,{"date":124,"score":121,"percentile":125},"2026-07-23",0.9538,{"date":97,"score":57,"percentile":127},0.96649,{"date":129,"score":57,"percentile":130},"2026-07-25",0.96653,{"date":132,"score":57,"percentile":133},"2026-07-26",0.96656,{"date":135,"score":57,"percentile":133},"2026-07-27",{"date":137,"score":57,"percentile":138},"2026-07-28",0.96659,{"date":140,"score":57,"percentile":141},"2026-07-29",0.96658,{"date":143,"score":57,"percentile":144},"2026-07-30",0.96664,{"date":146,"score":57,"percentile":147},"2026-07-31",0.96666,{"date":149,"score":57,"percentile":150},"2026-08-01",0.96667,{"date":152,"score":57,"percentile":147},"2026-08-02",{"date":154,"score":57,"percentile":150},"2026-08-03",{"date":156,"score":57,"percentile":157},"2026-08-04",0.9667,{"date":159,"score":57,"percentile":160},"2026-08-05",0.96673,{"date":162,"score":57,"percentile":163},"2026-08-06",0.96676,{"date":165,"score":57,"percentile":166},"2026-08-07",0.9668,{"date":168,"score":57,"percentile":169},"2026-08-08",0.96681,{"date":171,"score":57,"percentile":166},"2026-08-09",{"date":173,"score":57,"percentile":169},"2026-08-10",{"date":175,"score":57,"percentile":176},"2026-08-11",0.96687,{"date":178,"score":57,"percentile":179},"2026-08-12",0.96695,{"date":181,"score":57,"percentile":182},"2026-08-13",0.96698,{"date":184,"score":57,"percentile":185},"2026-08-14",0.96702,{"date":187,"score":57,"percentile":188},"2026-08-15",0.9671,{"date":190,"score":57,"percentile":191},"2026-08-16",0.96713,{"date":193,"score":57,"percentile":194},"2026-08-17",0.96712,{"date":196,"score":57,"percentile":197},"2026-08-18",0.96715,{"date":199,"score":57,"percentile":200},"2026-08-19",0.96729,{"date":202,"score":57,"percentile":203},"2026-08-20",0.96734,{"date":205,"score":57,"percentile":206},"2026-08-21",0.96739,{"date":101,"score":57,"percentile":102},[209,214],{"source":61,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":210,"cvss_v4_0":9},{"baseScore":59,"baseSeverity":211,"vectorString":62,"impactScore":212,"exploitabilityScore":213},"HIGH",9.8,5.6,{"source":67,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":215,"cvss_v4_0":9},{"baseScore":59,"baseSeverity":211,"vectorString":62,"impactScore":212,"exploitabilityScore":213},[217],{"ecosystem":9,"name":55,"vendor":218,"product":218,"cpe_part":219,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":220},"dd-wrt","o",[221],{"version":222,"is_range":54,"range_type":223,"version_start":9,"version_start_type":9,"version_end":224,"version_end_type":225,"fixed_in":9},"lt45724","cpe","45724","excluding"]