THREAT INTELLIGENCE CYBERTTAKv3.0.3.0
LIVE FEED ACTIVE
← Back to Intel Feed
Secure route: /intel/ai-cve-2021-27137-dd-wrt-stack-based-buffer-overflow
criticalCVE-2021-271372026-07-21Vector: network

CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow

A security vulnerability in DD-WRT firmware allows attackers to remotely take control of affected networking devices by sending malicious data to the UPnP feature.

Decision Context

English Brief

A security vulnerability in DD-WRT firmware allows attackers to remotely take control of affected networking devices by sending malicious data to the UPnP feature.

الموجز العربي

CVE-2021-27137: ثغرة تجاوز سعة المخزن المؤقت في DD-WRT

توجد ثغرة أمنية في برمجيات DD-WRT قد تسمح للمهاجمين بالسيطرة على أجهزة الشبكة المتأثرة عن بُعد عبر استغلال ميزة UPnP.

Affected Products
    Priority sectors
    TelecommunicationsEnterprise IT
    Immediate Actions
    1. 1Disable UPnP service in DD-WRT web interface
    2. 2Update firmware to the latest version via Administration > Firmware Upgrade
    3. 3Restrict access to the router management interface to trusted internal IP addresses only