Description
DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.
Problem types
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Product status
Credits
Selim Enes 'Enesdex' Karaduman
References
www.exploit-db.com/exploits/49730 (ExploitDB-49730)
dd-wrt.com/ (DD-WRT Official Vendor Homepage)
download1.dd-wrt.com/dd-wrtv2/downloads/betas/2021/ (DD-WRT Software Download Repository)
ssd-disclosure.com/ssd-advisory-dd-wrt-upnp-buffer-overflow/ (SSD Security Advisory for DD-WRT UPNP Buffer Overflow)
www.vulncheck.com/advisories/dd-wrt-upnp-buffer-overflow (VulnCheck Advisory: DD-WRT 45723 - UPNP Buffer Overflow)