Lucene search

K
cveMitreCVE-2009-2766
HistoryAug 14, 2009 - 3:16 p.m.

CVE-2009-2766

2009-08-1415:16:27
CWE-264
mitre
web.nvd.nist.gov
25
dd-wrt
24 sp1
httpd
management gui
remote attackers
settings
http requests

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.004

Percentile

75.0%

httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.

Affected configurations

Nvd
Node
dd-wrtdd-wrtMatch24sp1
VendorProductVersionCPE
dd-wrtdd-wrt24cpe:2.3:a:dd-wrt:dd-wrt:24:sp1:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.004

Percentile

75.0%

Related for CVE-2009-2766