PT-2009-2443 · New Media Net Gmbh · Dd-Wrt
Gat3Way
·
Published
2009-08-14
·
Updated
2017-09-29
·
CVE-2008-6974
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
DD-WRT versions 24 sp1 and earlier
Description:
The issue allows remote attackers to hijack the authentication of administrators for various requests, including executing arbitrary commands via the
ping ip parameter, changing administrative credentials via the http username and http passwd parameters, enabling remote administration via the remote management parameter, and configuring port forwarding via certain from, to, ip, and pro parameters.Recommendations:
For DD-WRT versions 24 sp1 and earlier, consider disabling the apply.cgi module until a patch is available to prevent exploitation of the CSRF vulnerabilities. Restrict access to the administrative interface to minimize the risk of unauthorized changes. Avoid using the vulnerable parameters, such as
ping ip, http username, http passwd, remote management, from, to, ip, and pro, in the affected API endpoint until the issue is resolved.Exploit
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dd-Wrt