CVE-2021-27137CISA KEVEPSS p90.2%

CVE-2021-27137DD-WRT Stack-Based Buffer Overflow Vulnerability

DD-WRT / DD-WRT

Description

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability.

Scoring

CVSS 8.1 ()
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS4.00% probability of exploitation · percentile 90.2% · 2026-10-05T12:00:23Z
Last modified2026-07-22

CISA KEV entry

Added to KEV: 2026-07-21

Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.