CVE-2024-45888: Command Injection
DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the action parameter in cgi-bin/mainfunction.cgi is set to setapmapconfig.'
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45888?
CVE-2024-45888 is classified as a high severity vulnerability due to its potential for remote command execution.
How does CVE-2024-45888 affect DrayTek Vigor3900 devices?
CVE-2024-45888 allows an attacker to execute arbitrary commands on the DrayTek Vigor3900 by manipulating the 'action' parameter in the affected CGI script.
How do I fix CVE-2024-45888?
To mitigate CVE-2024-45888, users should update their DrayTek Vigor3900 firmware to the latest version that addresses this vulnerability.
What is the exploit vector for CVE-2024-45888?
CVE-2024-45888 can be exploited through a specially crafted HTTP request targeting the vulnerable CGI endpoint.
Is CVE-2024-45888 being actively exploited in the wild?
As of now, there are no confirmed reports indicating that CVE-2024-45888 is being actively exploited in the wild.