First published: Wed Mar 15 2023(Updated: )
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigor2960 Firmware | =1.5.1.4 | |
DrayTek Vigor2960 | ||
All of | ||
Draytek Vigor2960 Firmware | =1.5.1.4 | |
DrayTek Vigor2960 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the DrayTek Vigor2960 command injection vulnerability is CVE-2023-24229.
The severity of the DrayTek Vigor2960 command injection vulnerability is high, with a CVSS score of 7.8.
The DrayTek Vigor2960 firmware version 1.5.1.4 is affected by the command injection vulnerability.
To fix the DrayTek Vigor2960 command injection vulnerability, update the firmware to a version that has addressed the issue.
You can find more information about the DrayTek Vigor2960 command injection vulnerability on the GitHub page and the official DrayTek website.