Stack-based Buffer Overflow (CWE-121)
CWE-121 is a Variant in which the overwritten buffer is on the stack, usually a local variable or, rarely, a function parameter. MITRE notes that stack overflow is an ambiguous term because it can also mean stack exhaustion from deep recursion, so it discourages that phrasing.
About CWE-121
The usual result is a crash or infinite loop. Overwriting stack memory can also allow arbitrary code execution, which may then subvert other security services.
Mitigations
- +Implement bounds checking on all input written to stack buffers.
- +Replace dangerous functions with safer equivalents that check for boundary errors.
- +Enable compiler stack protections such as canary-based detection (/GS, StackGuard, ProPolice) as defense in depth.
- +Use ASLR and position-independent executables to make code locations unpredictable.
- +Wrap risky APIs in an abstraction library, noting this is not a complete solution.
Detection
Fuzzing and automated static analysis are rated highly effective, and runtime checkers such as AddressSanitizer help during testing.
CWE-121 Vulnerabilities
17 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-7273 | Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability | Zyxel | 8.8 | 2.5% | KEV | 2026-06-16 |
| CVE-2021-27137 | DD-WRT Stack-Based Buffer Overflow Vulnerability | DD-WRT | 8.1 | 4.0% | KEV | 2026-07-16 |
| CVE-2025-53521 | BigIP APM Vulnerability | F5 | 9.8 | 2.3% | KEV | 2025-10-15 |
| CVE-2025-32756 | Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability | Fortinet | 9.6 | 29.8% | KEV | 2025-05-13 |
| CVE-2025-42599 | Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability | QUALITIA CO., LTD. | 9.8 | 3.3% | KEV | 2025-04-18 |
| CVE-2025-22457 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Ivanti | 9.0 | 100.0% | KEV | 2025-04-03 |
| CVE-2025-0282 | Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability | Ivanti | 9.0 | 100.0% | KEV | 2025-01-08 |
| CVE-2022-20699 | Cisco Small Business RV Series Routers Vulnerabilities | Cisco | 10.0 | 72.5% | KEV | 2022-02-10 |
| CVE-2022-20708 | Cisco Small Business RV Series Routers Vulnerabilities | Cisco | 10.0 | 14.9% | KEV | 2022-02-10 |
| CVE-2022-20701 | Cisco Small Business RV Series Routers Vulnerabilities | Cisco | 10.0 | 9.7% | KEV | 2022-02-10 |
| CVE-2022-20703 | Cisco Small Business RV Series Routers Vulnerabilities | Cisco | 10.0 | 9.2% | KEV | 2022-02-10 |
| CVE-2022-20700 | Cisco Small Business RV Series Routers Vulnerabilities | Cisco | 10.0 | 5.7% | KEV | 2022-02-10 |
| CVE-2021-20038 | SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability | SonicWall | 9.8 | 99.9% | KEV | 2021-12-08 |
| CVE-2020-5735 | Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability | - | 8.8 | 36.2% | KEV | 2020-04-08 |
| CVE-2026-2329 | Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow | Grandstream | 9.3 | 41.3% | 2026-02-18 | |
| CVE-2026-0826 | Poly Voice – Possible Remote Control of Certain Poly Devices | HP Inc. | 9.2 | 32.2% | 2026-06-01 | |
| CVE-2026-10187 | Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow | Totolink | 10.0 | 7.3% | 2026-05-31 |
Most Affected Vendors
Related Weaknesses
Tool Categories That Address This Weakness
Frequently Asked Questions
What is CWE-121?→
CWE-121 is a stack-based buffer overflow: data written beyond a buffer that was allocated on the call stack.
Why does MITRE avoid the term 'stack overflow'?→
The phrase is also used for stack exhaustion caused by excessive recursion. MITRE discourages it for either case because of that ambiguity.
How many exploited vulnerabilities are classified as CWE-121?→
This database lists 17 CVE records mapped to CWE-121 by their CVE Numbering Authority. 14 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-7273, CVE-2021-27137, CVE-2025-53521.
Sources
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.