CVE-2020-13976: OS Command Injection
DISPUTED An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software maintainers consider the report invalid because it refers to an old software version, requires administrative privileges, and does not provide access beyond that already available to administrative users.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13976?
CVE-2020-13976 is a vulnerability in DD-WRT through version 16214 that allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command.
What is the severity of CVE-2020-13976?
The severity of CVE-2020-13976 is high with a CVSS score of 8.8.
How can remote attackers exploit CVE-2020-13976?
Remote attackers can exploit CVE-2020-13976 by using shell metacharacters in the host field of the ping command, potentially allowing them to execute arbitrary commands.
Is there a fix available for CVE-2020-13976?
As of now, there is no information available about a fix or patch for CVE-2020-13976. It is recommended to stay updated with the latest software releases and security advisories.
Where can I find more information about CVE-2020-13976?
You can find more information about CVE-2020-13976 on the official DD-WRT website at https://svn.dd-wrt.com/ticket/7039.