vendor:
DD-WRT
by:
Selim Enes 'Enesdex' Karaduman
7.5
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: DD-WRT
Affected Version From: 45723
Affected Version To: 45723
Patch Exists: NO
Related CWE:
CPE: o:dd-wrt:dd-wrt:45723
Platforms Tested: TP-Link Archer C7
2021
DD-WRT 45723 – UPNP Buffer Overflow (PoC)
This exploit demonstrates a buffer overflow vulnerability in the UPNP service of DD-WRT version 45723 or prior. By sending a specially crafted packet to the target IP address, an attacker can overflow the buffer and potentially execute arbitrary code.
Mitigation:
The vendor has not provided a patch for this vulnerability. It is recommended to disable UPNP or upgrade to a newer version of DD-WRT if available.