<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — DD-WRT</title><description>DD-WRT is an open-source firmware for consumer and SOHO wireless routers, running on hardware from a range of manufacturers. Coverage tracks CVEs against DD-WRT&apos;s own daemons — UPnP/SSDP, the httpd web UI, and network services — that reach the CISA KEV catalog or otherwise show up in unpatched-population telemetry. Combined article + CVE feed for the DD-WRT beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2021-27137 — DD-WRT SSDP Stack-Based Buffer Overflow (UPnP)</title><link>https://0daynews.com/cve/cve-2021-27137/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2021-27137/</guid><description>An unsafe strcpy in DD-WRT&apos;s SSDP handling lets an unauthenticated attacker overflow an internal buffer via the UPnP listener and trigger code execution. Added to CISA KEV on 2026-07-21.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>DD-WRT</category><category>high</category><category>cve</category></item><item><title>DD-WRT UPnP flaw CVE-2021-27137 added to CISA KEV</title><link>https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-cisa-kev-dd-wrt-cve-2021-27137-upnp-ssdp-strcpy-r45724/</guid><description>CISA added DD-WRT&apos;s 2021 SSDP-parsing buffer overflow to KEV on 2026-07-21. Unauthenticated attackers can reach it on routers with UPnP left enabled.</description><pubDate>Tue, 21 Jul 2026 19:15:00 GMT</pubDate><category>DD-WRT</category><category>article</category></item></channel></rss>