Loading
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers to execute arbitrary commands via shell metacharacters in a request to a cgi-bin/ URI.
Use CWE-20, Dd-Wrt vendor hub and Dd-Wrt product page to widen CVE-2009-2765 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-27631, CVE-2020-13976 and CVE-2012-6297 for nearby disclosures in the same product family.