CVE
- Id
- 40201
- CVE No.
- CVE-2009-2766
- Status
- Candidate
- Description
- httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.
- Phase
- Assigned (20090814)
- Votes
- None (candidate not yet proposed)
- Comments