CVE-2024-45884: Command Injection
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the action parameter in cgi-bin/mainfunction.cgi is set to setSWMGroup.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45884?
CVE-2024-45884 is considered a critical vulnerability due to its potential for command injection post-authentication.
How do I fix CVE-2024-45884?
To fix CVE-2024-45884, update the DrayTek Vigor3900 to a version that addresses this vulnerability.
What is the impact of CVE-2024-45884 on DrayTek Vigor3900?
The impact of CVE-2024-45884 allows an authenticated attacker to execute arbitrary commands on the device.
Which software versions are affected by CVE-2024-45884?
CVE-2024-45884 affects DrayTek Vigor3900 running firmware version 1.5.1.3.
How can I determine if my DrayTek Vigor3900 is vulnerable to CVE-2024-45884?
You can determine if your DrayTek Vigor3900 is vulnerable by checking if it is running firmware version 1.5.1.3 or earlier and testing the `action` parameter in `cgi-bin/mainfunction.cgi`.