CVE-2021-42911: Critical severity draytek vigor 2960 firmware vulnerability
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-42911?
CVE-2021-42911 is a Format String vulnerability that exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file.
How can a remote user exploit CVE-2021-42911?
A remote user can exploit CVE-2021-42911 by sending a crafted HTTP message containing a malformed QUERY STRING, which could allow them to execute arbitrary code.
What is the severity of CVE-2021-42911?
CVE-2021-42911 has a severity rating of 9.8 (Critical).
Which DrayTek products are affected by CVE-2021-42911?
The DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 are affected by CVE-2021-42911.
Is the DrayTek Vigor 2960 vulnerable to CVE-2021-42911?
Yes, the DrayTek Vigor 2960 <= 1.5.1.3 is vulnerable to CVE-2021-42911.