CVE-2024-45889: Command Injection
Published Nov 4, 2024
·Updated
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the action parameter in cgi-bin/mainfunction.cgi is set to commandTable.
Affected Software
1 affected component
DrayTek Vigor3900
Event History
Nov 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45889?
CVE-2024-45889 is classified as a high severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2024-45889?
To remediate CVE-2024-45889, apply the latest firmware update from DrayTek that addresses the vulnerability.
3
What systems are impacted by CVE-2024-45889?
CVE-2024-45889 affects the DrayTek Vigor3900 running the firmware version 1.5.1.3.
4
What type of vulnerability is CVE-2024-45889?
CVE-2024-45889 is a post-authentication command injection vulnerability.
5
What can be exploited in CVE-2024-45889?
In CVE-2024-45889, the 'action' parameter in 'cgi-bin/mainfunction.cgi' can be manipulated to execute arbitrary commands.