CVE-2009-2766: High severity dd-wrt vulnerability
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2766?
CVE-2009-2766 is considered a high severity vulnerability due to its ability to allow unauthorized remote access to critical settings.
How do I fix CVE-2009-2766?
To fix CVE-2009-2766, upgrade to a version of DD-WRT that requires administrative authentication for the management GUI.
What platforms are affected by CVE-2009-2766?
CVE-2009-2766 affects DD-WRT version 24-sp1 specifically, targeting the management GUI.
What type of attack does CVE-2009-2766 facilitate?
CVE-2009-2766 facilitates remote attacks that exploit lack of authentication to modify router settings via HTTP requests.
Is CVE-2009-2766 easy to exploit?
Yes, CVE-2009-2766 is easy to exploit since it does not require any authentication, allowing immediate access to vulnerable devices.