Record summary

CVE-2021-47854 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

DD-WRT version 45723 contains a buffer overflow vulnerability in the UPNP network discovery service that allows remote attackers to potentially execute arbitrary code. Attackers can send crafted M-SEARCH packets with oversized UUID payloads to trigger buffer overflow conditions on the target device.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List45723affected

Proofs of concept

1

Catalogued exploits

ExploitDBDD-WRT 45723 - UPNP Buffer Overflow (PoC)ExploitDB exploitby EnesdexNot analyzed1 file
ExploitDB

PoC details

References

6