Skip to main content

About CWE-121

The usual result is a crash or infinite loop. Overwriting stack memory can also allow arbitrary code execution, which may then subvert other security services.

MITRE name
Stack-based Buffer Overflow
Abstraction
Variant: linked to a certain type of product, typically a specific language or technology
Status
Draft
Also known as
Stack Overflow, Stack Buffer Overflow

Mitigations

  • +Implement bounds checking on all input written to stack buffers.
  • +Replace dangerous functions with safer equivalents that check for boundary errors.
  • +Enable compiler stack protections such as canary-based detection (/GS, StackGuard, ProPolice) as defense in depth.
  • +Use ASLR and position-independent executables to make code locations unpredictable.
  • +Wrap risky APIs in an abstraction library, noting this is not a complete solution.

Detection
Fuzzing and automated static analysis are rated highly effective, and runtime checkers such as AddressSanitizer help during testing.

CWE-121 Vulnerabilities

17 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-7273
Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability
Zyxel8.82.5%KEV2026-06-16
CVE-2021-27137
DD-WRT Stack-Based Buffer Overflow Vulnerability
DD-WRT8.14.0%KEV2026-07-16
CVE-2025-53521
BigIP APM Vulnerability
F59.82.3%KEV2025-10-15
CVE-2025-32756
Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Fortinet9.629.8%KEV2025-05-13
CVE-2025-42599
Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability
QUALITIA CO., LTD.9.83.3%KEV2025-04-18
CVE-2025-22457
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti9.0100.0%KEV2025-04-03
CVE-2025-0282
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Ivanti9.0100.0%KEV2025-01-08
CVE-2022-20699
Cisco Small Business RV Series Routers Vulnerabilities
Cisco10.072.5%KEV2022-02-10
CVE-2022-20708
Cisco Small Business RV Series Routers Vulnerabilities
Cisco10.014.9%KEV2022-02-10
CVE-2022-20701
Cisco Small Business RV Series Routers Vulnerabilities
Cisco10.09.7%KEV2022-02-10
CVE-2022-20703
Cisco Small Business RV Series Routers Vulnerabilities
Cisco10.09.2%KEV2022-02-10
CVE-2022-20700
Cisco Small Business RV Series Routers Vulnerabilities
Cisco10.05.7%KEV2022-02-10
CVE-2021-20038
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
SonicWall9.899.9%KEV2021-12-08
CVE-2020-5735
Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability
-8.836.2%KEV2020-04-08
CVE-2026-2329
Grandstream GXP1600 VoIP Phones - Unauthenticated stack buffer overflow
Grandstream9.341.3%2026-02-18
CVE-2026-0826
Poly Voice – Possible Remote Control of Certain Poly Devices
HP Inc.9.232.2%2026-06-01
CVE-2026-10187
Totolink N300RH Web Management wireless.so setWiFiBasicConfig stack-based overflow
Totolink10.07.3%2026-05-31

Most Affected Vendors

Related Weaknesses

Frequently Asked Questions

What is CWE-121?→

CWE-121 is a stack-based buffer overflow: data written beyond a buffer that was allocated on the call stack.

Why does MITRE avoid the term 'stack overflow'?→

The phrase is also used for stack exhaustion caused by excessive recursion. MITRE discourages it for either case because of that ambiguity.

How many exploited vulnerabilities are classified as CWE-121?→

This database lists 17 CVE records mapped to CWE-121 by their CVE Numbering Authority. 14 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 3 to known ransomware campaigns. Examples include CVE-2026-7273, CVE-2021-27137, CVE-2025-53521.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.