Loading
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.
Cite this page
CVE-2009-2766. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2009-2766
Use CWE-264, Dd-Wrt vendor hub and Dd-Wrt product page to widen CVE-2009-2766 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-27631, CVE-2020-13976 and CVE-2012-6297 for nearby disclosures in the same product family.