High severity8.8NVD Advisory· Published Feb 6, 2020· Updated Jun 16, 2026
CVE-2012-6297
CVE-2012-6297
Description
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
Affected products
3- DD-WRT/DD-WRTdescription
Patches
Vulnerability mechanics
References
4- lists.openwall.net/bugtraq/2013/07/12/2nvdThird Party Advisory
- packetstormsecurity.com/files/cve/CVE-2012-6297nvdThird Party AdvisoryVDB Entry
- seclists.org/fulldisclosure/2013/Oct/241nvdMailing ListThird Party Advisory
- vuldb.comnvdPermissions Required
News mentions
0No linked articles in our index yet.