CVE-2021-43118: Command Injection
Published Mar 29, 2022
·Updated
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.
Affected Software
6 affected components
DrayTek Vigor2960 Firmware=1.5.1.3
DrayTek Vigor2960
DrayTek Vigor3900 Firmware=1.5.1.3
DrayTek Vigor3900
DrayTek Vigor300b Firmware=1.5.1.3
DrayTek Vigor300B
Event History
Mar 29, 2022
CVE Published
via MITRE·07:37 PM
Data Sourced
via MITRE·07:37 PM
Description
Frequently Asked Questions
1
What is CVE-2021-43118?
CVE-2021-43118 is a Remote Command Injection vulnerability in DrayTek Vigor routers.
2
How does CVE-2021-43118 affect DrayTek Vigor 2960?
CVE-2021-43118 affects DrayTek Vigor 2960 1.5.1.3 firmware by allowing remote attackers to execute arbitrary code.
3
What is the severity of CVE-2021-43118?
CVE-2021-43118 has a severity rating of 9.8 (Critical).
4
How can I fix CVE-2021-43118?
To fix CVE-2021-43118, update DrayTek Vigor 2960 firmware to version 1.5.1.4 or later.
5
Are DrayTek Vigor 3900 and DrayTek Vigor 300B affected by CVE-2021-43118?
Yes, DrayTek Vigor 3900 1.5.1.3 firmware and DrayTek Vigor 300B 1.5.1.3 firmware are also affected by CVE-2021-43118.