CVE-2008-6974: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the pingip parameter; (2) change the administrative credentials via the httpusername and httppasswd parameters; (3) enable remote administration via the remotemanagement parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6974?
CVE-2008-6974 is considered a high severity vulnerability due to its exploitation potential via cross-site request forgery.
How do I fix CVE-2008-6974?
To fix CVE-2008-6974, update DD-WRT to a version later than 24 SP1 that addresses these CSRF vulnerabilities.
What types of attacks are possible with CVE-2008-6974?
CVE-2008-6974 allows attackers to execute arbitrary commands and change administrative credentials through CSRF attacks.
Who is affected by CVE-2008-6974?
Administrators using DD-WRT version 24 SP1 or earlier are affected by CVE-2008-6974 vulnerabilities.
Is there a workaround for CVE-2008-6974?
As a workaround for CVE-2008-6974, it's recommended to disable remote access and ensure proper CSRF protections are in place.