CVE-2024-45891: Command Injection
Published Nov 4, 2024
·Updated
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the action parameter in cgi-bin/mainfunction.cgi is set to deletewlanprofile.
Affected Software
1 affected component
DrayTek Vigor3900
Event History
Nov 4, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-45891?
CVE-2024-45891 is classified as a medium severity post-authentication command injection vulnerability.
2
How do I fix CVE-2024-45891?
To mitigate CVE-2024-45891, users should upgrade the DrayTek Vigor3900 firmware to a version that addresses this vulnerability.
3
What systems are affected by CVE-2024-45891?
CVE-2024-45891 affects DrayTek Vigor3900 routers running firmware version 1.5.1.3.
4
What is the impact of CVE-2024-45891?
The impact of CVE-2024-45891 allows an authenticated user to execute arbitrary commands on the router.
5
When was CVE-2024-45891 disclosed?
CVE-2024-45891 was disclosed in the year 2024.