Indicator
Type cve · source AlienVault OTX
Verdict
KNOWN VULNERABILITY
What this is
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would overflow an internal fixed buffer. Exploitation requires the DD-WRT user to enable UPnP (which is off by default, and only listens on internal interfaces by default). This occurs in ssdp_msearch (reachable by an M-SEARCH request).
Threat detail
Exploitation status and malware-family attribution from stored fields.
Vulnerability intel
Local EPSS row, KEV flag, and catalog notes from stored metadata only.
Affected products
Vendor/product strings parsed from local CPE URIs (no inferred ATT&CK).
| Product | CPE (truncated) |
|---|---|
| cpe:2.3:o:dd-wrt:dd-wrt:*:*:*:*:*:*:*:* | cpe:2.3:o:dd-wrt:dd-wrt:*:*:*:*:*:*:*:* |
Graph preview
Neighborhood topology — open the graph for interactive pivots.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Structured pivots from local graph context.
See edges, pivots, and corroboration at a glance.
Full inspector with neighbor expansion.