Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
9.8
CVE-2022-27631
- EPSS 2.52%
- Veröffentlicht 05.08.2022 22:15:11
- Zuletzt bearbeitet 21.11.2024 06:56:03
A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerabili...
8.8
CVE-2020-13976
- EPSS 0.76%
- Veröffentlicht 09.06.2020 14:15:10
- Zuletzt bearbeitet 21.11.2024 05:02:16
An issue was discovered in DD-WRT through 16214. The Diagnostic page allows remote attackers to execute arbitrary commands via shell metacharacters in the host field of the ping command. Exploitation through CSRF might be possible. NOTE: software mai...
9.3
CVE-2012-6297
- EPSS 0.65%
- Veröffentlicht 06.02.2020 18:15:12
- Zuletzt bearbeitet 21.11.2024 01:45:58
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
1