Записи DD-WRT
8 опубликованных записей вендора dd-wrt.
Профиль для исследователя
- Попали в KEV
- 1 · 12,5 %
- С эксплойтом
- 2 · 25 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 5 дн.
Повторяющиеся классы
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-121 Stack-based Buffer Overflow1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
- CWE-787 Out-of-bounds Write1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
63На этой неделе | CVE-2021-27137Готовый эксплойт | An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724.dd-wrt · dd-wrt · CWE-121 | Высокая8,1 | KEV | 4,0 % | 16 июл. 2026 г. |
58В плане | CVE-2009-2765Готовый эксплойт | httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrarydd-wrt · dd-wrt · CWE-20 | Высокая8,3 | — | 82,5 % | 14 авг. 2009 г. |
39Наблюдать | CVE-2022-27631Эксплойта нет | A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599.dd-wrt · dd-wrt · CWE-787 | Критическая9,8 | — | 1,2 % | 5 авг. 2022 г. |
36Наблюдать | CVE-2020-13976Эксплойта нет | An issue was discovered in DD-WRT through 16214.dd-wrt · dd-wrt · CWE-78 | Высокая8,8 | — | 1,8 % | 9 июн. 2020 г. |
36Наблюдать | CVE-2012-6297Эксплойта нет | Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-charactdd-wrt · dd-wrt · CWE-352 | Высокая8,8 | — | 1,7 % | 6 февр. 2020 г. |
32Наблюдать | CVE-2009-2766Proof of concept | httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which aldd-wrt · dd-wrt · CWE-264 | Высокая7,5 | — | 5,1 % | 14 авг. 2009 г. |
27Наблюдать | CVE-2008-6974Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the audd-wrt · dd-wrt · CWE-352 | Средняя6,8 | — | 1,5 % | 14 авг. 2009 г. |
27Наблюдать | CVE-2008-6975Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authenticationdd-wrt · dd-wrt · CWE-352 | Средняя6,8 | — | 1,3 % | 14 авг. 2009 г. |
- CVE-2021-2713763На этой неделе
An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 4 %dd-wrt · dd-wrt16 июл. 2026 г.
- CVE-2009-276558В плане
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary
ВысокаяCVSS 8,3Готовый эксплойтEPSS 83 %dd-wrt · dd-wrt14 авг. 2009 г.
- CVE-2022-2763139Наблюдать
A memory corruption vulnerability exists in the httpd unescape functionality of DD-WRT Revision 32270 - Revision 48599.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %dd-wrt · dd-wrt5 авг. 2022 г.
- CVE-2020-1397636Наблюдать
An issue was discovered in DD-WRT through 16214.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dd-wrt · dd-wrt9 июн. 2020 г.
- CVE-2012-629736Наблюдать
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-charact
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %dd-wrt · dd-wrt6 февр. 2020 г.
- CVE-2009-276632Наблюдать
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which al
ВысокаяCVSS 7,5Proof of conceptEPSS 5 %dd-wrt · dd-wrt14 авг. 2009 г.
- CVE-2008-697427Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp1 and earlier allow remote attackers to hijack the au
СредняяCVSS 6,8Proof of conceptEPSS 1 %dd-wrt · dd-wrt14 авг. 2009 г.
- CVE-2008-697527Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijack the authentication
СредняяCVSS 6,8Proof of conceptEPSS 1 %dd-wrt · dd-wrt14 авг. 2009 г.