Impact
An unsafe strcpy in DD‑WRT’s UPnP SSDP handling (ssdp_msearch) allows an unauthenticated attacker to send a crafted M‑SEARCH request that overflows an internal fixed buffer, leading to a stack‑based buffer overflow classified as CWE‑121. This flaw could potentially enable arbitrary code execution on the router.
Affected Systems
DD‑WRT firmware releases earlier than changeset 45724 are affected. The vulnerability only exists when UPnP is enabled, which is disabled by default and listens only on internal interfaces unless the device owner re‑configures it.
Risk and Exploitability
The CVSS base score of 8.1 marks the flaw as high severity, and the EPSS score of 16% indicates a non‑trivial likelihood of exploitation. Based on the description, the attack vector requires an unauthenticated attacker to send an M‑SEARCH packet to the UPnP service, implying that the router’s UPnP interface must be reachable from the attacker’s network. The flaw is listed in the CISA KEV catalog, and the C0xmo botnet has weaponized it to disrupt rival malware on DD‑WRT systems.
OpenCVE Enrichment