DDWRT.HTTP.Daemon.Arbitrary.Command.Execution

description-logoDescription

This indicates a possible attack toward a remote command-injection vulnerability in DD-WRT HTTP server.
The vulnerability is due to the software's failure to adequately check user-supplied data in HTTP requests. Remote attackers may exploit this to execute arbitrary code.

affected-products-logoAffected Products

DD-WRT DD-WRT v24.sp1
DD-WRT DD-WRT v24-sp1
DD-WRT DD-WRT v24

Impact logoImpact

System compromise

recomended-action-logoRecommended Actions

Currently we are not aware of any vendor-supplied patch or update.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)