DD-WRT 缓冲区溢出漏洞(CVE-2021-27137) CVE-2021-27137

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

# SSD Advisory – DD-WRT UPNP Buffer Overflow March 24, 2021 [SSD Disclosure / Technical Lead](https://ssd-disclosure.com/author/noamr/) [Uncategorized](https://ssd-disclosure.com/category/uncategorized/) **TL;DR** Find out how a vulnerability in DD-WRT allows an unauthenticated attacker to overflow an internal buffer used by UPNP and trigger a code execution vulnerability. **Vulnerability Summary** DD-WRT is “is Linux-based firmware for wireless routers and access points. Originally designed for the Linksys WRT54G series, it now runs on a wide variety of models”. Use of user supplied data, arriving via UPNP packet, is copied into an internal buffer of DD-WRT. This buffer being limited in side – while user supplied data is not allows a remote attacker to trigger a buffer overflow. **CVE** CVE-2021-27137 ***\*Credit\**** An independent security researchers, Selim Enes Karaduman, has reported this vulnerability to the SSD Secure Disclosure program. **Affected Versions** DD-WRT with...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息