CVE-2008-6975: CSRF
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary commands via the pingip parameter; (2) change the administrative credentials via the httpusername and httppasswd parameters; (3) enable remote administration via the remotemanagement parameter; or (4) configure port forwarding via certain from, to, ip, and pro parameters. NOTE: This issue reportedly exists because of a "weak ... anti-CSRF fix" implemented in 24 sp2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-6975?
CVE-2008-6975 is considered a high severity vulnerability due to its potential to allow remote attackers to hijack administrator authentication.
How do I fix CVE-2008-6975?
To fix CVE-2008-6975, upgrade to a newer version of DD-WRT that resolves these CSRF vulnerabilities.
What are the risks associated with CVE-2008-6975?
The risks associated with CVE-2008-6975 include unauthorized access and control over the DD-WRT router by exploiting CSRF vulnerability.
Who is affected by CVE-2008-6975?
Users running DD-WRT version 24-sp2 are affected by CVE-2008-6975.
What types of attacks can exploit CVE-2008-6975?
CVE-2008-6975 can be exploited through cross-site request forgery attacks that allow execution of arbitrary commands and credential changes.