httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://www.exploit-db.com/exploits/9209 | exploit |
http://www.dd-wrt.com/phpBB2/viewtopic.php?t=55173 | exploit |