CVE-2012-6297: DD-WRT
High severity, CVSS 8.8. EPSS: 1.7% chance of exploitation in the next 30 days.
Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.
Affected products
- DD-WRT DD-WRT: version 24 only
Published 2020-02-06. Last modified 2026-06-16.