Description
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authenticationen·The Hacker News· Exploited Windmill platform web-app
- COXMO Botnet Variant: New Advanced Threat Exploits Router Firmwareen-us·Daily CyberSecurity (securityonline.info)· Exploited COXMO botnet variant ddos-botnet
- ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and Moreen·The Hacker News· Roundup GitHub repositories supply-chain
- Ботнет C0XMO атакует маршрутизаторы с прошивкой DD-WRTru-ru·Хакер (xakep.ru)· Exploited DD-WRT ddos-botnet
- C0XMO botnet spreads via DD-WRT router flaw, kills rival malwareen-us·BleepingComputer· Research DD-WRT router firmware ddos-botnet
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2021-27137 and every CVE in our database. Create a free account — no credit card required.
Create Free Account