First published: Tue Mar 29 2022(Updated: )
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigor2960 Firmware | <=1.5.1.3 | |
DrayTek Vigor2960 | ||
Draytek Vigor3900 Firmware | <=1.5.1.3 | |
DrayTek Vigor3900 | ||
Draytek Vigor300b Firmware | <=1.5.1.3 | |
Draytek Vigor300b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-42911 is a Format String vulnerability that exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file.
A remote user can exploit CVE-2021-42911 by sending a crafted HTTP message containing a malformed QUERY STRING, which could allow them to execute arbitrary code.
CVE-2021-42911 has a severity rating of 9.8 (Critical).
The DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 are affected by CVE-2021-42911.
Yes, the DrayTek Vigor 2960 <= 1.5.1.3 is vulnerable to CVE-2021-42911.