Products: 1
    Vulnerabilities: 9
    Known Exploited: 1
    2
    Critical Level Threats
    5
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-27137

    An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).

    Last Modified: Aug 04, 2026
    Published: Jul 16, 2026

    CVE-2021-47854

    DD-WRT 45723 - UPNP Buffer Overflow

    Last Modified: Jul 28, 2026
    Published: Jan 21, 2026

    CVE-2022-27631

    A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.

    Last Modified: Apr 15, 2025
    Published: Aug 05, 2022

    CVE-2020-13976

    An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users

    Last Modified: Nov 21, 2024
    Published: Jun 09, 2020

    CVE-2012-6297

    Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.

    Last Modified: Nov 21, 2024
    Published: Feb 06, 2020
    Items Per Page
    Dd-Wrt Vulnerabilities & Security CVEs | CVE-DB