Loading
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
Cite this page
CVE-2012-6297. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2012-6297
Use CWE-352, Dd-Wrt vendor hub and Dd-Wrt product page to widen CVE-2012-6297 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-27631, CVE-2020-13976 and CVE-2009-2765 for nearby disclosures in the same product family.