CVE-2009-2765: Input Validation
Published Aug 14, 2009
·Updated
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.
Affected Software
1 affected component
DD-WRT DD-WRT<=24
Remediation
Patch Available
Patch Available
Event History
Aug 14, 2009
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Nov 26, 2025
News Published
via The Register·06:44 PM
News Published
via The Register·06:48 PM
Frequently Asked Questions
1
What is the severity of CVE-2009-2765?
CVE-2009-2765 is considered a high-severity vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2009-2765?
To fix CVE-2009-2765, update to DD-WRT firmware version build 12533 or later.
3
What systems are affected by CVE-2009-2765?
CVE-2009-2765 affects DD-WRT versions prior to build 12533, specifically those using the management GUI.
4
Can CVE-2009-2765 be exploited remotely?
Yes, CVE-2009-2765 can be exploited remotely by sending specially crafted requests to the vulnerable cgi-bin/ URI.
5
What exploitation methods are used in CVE-2009-2765?
CVE-2009-2765 allows attackers to execute arbitrary commands through the use of shell metacharacters in HTTP requests.