CVE-2009-2765

EXPLOITED

DD-WRT <build 12533 - RCE

Title source: llm

Description

httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappscgi
https://www.exploit-db.com/exploits/16856
exploitdb WRITEUP VERIFIED
by gat3way · textremotehardware
https://www.exploit-db.com/exploits/9209
exploitdb WORKING POC VERIFIED
by H D Moore · rubyremotelinux
https://www.exploit-db.com/exploits/10030
metasploit WORKING POC EXCELLENT
by gat3way, hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/ddwrt_cgibin_exec.rb

Scores

EPSS 0.8865
EPSS Percentile 99.5%

Details

VulnCheck KEV 2019-06-13
CWE
CWE-20
Status published
Products (1)
dd-wrt/dd-wrt < 24
Published Aug 14, 2009
Tracked Since Feb 18, 2026