CVE-2012-6297: CSRF
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2012-6297?
CVE-2012-6297 is a Command Injection vulnerability that exists via a CSRF in DD-WRT 24-sp2.
How does CVE-2012-6297 work?
CVE-2012-6297 allows a remote malicious user to cause a Denial of Service by exploiting a Command Injection vulnerability through specially crafted configuration values containing shell meta-characters.
What is the severity of CVE-2012-6297?
CVE-2012-6297 has a severity level of 8.8, which is considered critical.
How can I fix CVE-2012-6297?
To fix CVE-2012-6297, it is recommended to update DD-WRT to a version that does not have the vulnerability.
Where can I find more information about CVE-2012-6297?
More information about CVE-2012-6297 can be found at the following references: [1] [2] [3].