DD-WRT is a third-party firmware distribution for consumer and small-business routers that replaces the manufacturer's default operating system to extend functionality and device longevity. The vulnerability profile centers on the firmware product itself and reflects the complexity of wireless networking, embedded device management, and protocol handling inherent to router platforms. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dd Wrt over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2765HIGH httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a | Aug 14, 2009 | 8.3 | 83 | NO | YES |
CVE-2021-27137HIGH An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a re | Jul 16, 2026 | 8.1 | 81 | YES | NO |
CVE-2022-27631CRITICAL A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corrupti | Aug 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2009-2766HIGH httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings | Aug 14, 2009 | 7.5 | 30 | NO | YES |
CVE-2012-6297HIGH Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious | Feb 6, 2020 | 8.8 | 28 | NO | NO |
CVE-2008-6975MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) | Aug 14, 2009 | 6.8 | 26 | NO | YES |
CVE-2008-6974MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authentication of administrators for reque | Aug 14, 2009 | 6.8 | 26 | NO | YES |
CVE-2020-13976HIGH An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping co | Jun 9, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dd Wrt.
Media articles that mention a CVE ID that affects a product developed by Dd Wrt — matched by CVE ID, not by vendor name.