CVE-2024-45890: Command Injection
Published Nov 4, 2024
·Updated
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the action parameter in cgi-bin/mainfunction.cgi is set to downloadovpn.
Affected Software
1 affected component
DrayTek Vigor3900
Event History
Nov 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45890?
CVE-2024-45890 is classified as a medium-severity vulnerability due to its potential impact after authentication.
2
How do I fix CVE-2024-45890?
To mitigate CVE-2024-45890, update the DrayTek Vigor3900 firmware to the latest version provided by DrayTek.
3
What type of vulnerability is CVE-2024-45890?
CVE-2024-45890 is a post-authentication command injection vulnerability affecting the DrayTek Vigor3900.
4
Which systems are affected by CVE-2024-45890?
CVE-2024-45890 specifically affects the DrayTek Vigor3900 running firmware version 1.5.1.3.
5
What can an attacker achieve with CVE-2024-45890?
An attacker exploiting CVE-2024-45890 can execute arbitrary commands on the DrayTek Vigor3900 after successfully authenticating.