CVE-2024-48074: OS Command Injection
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48074?
CVE-2024-48074 is considered a critical vulnerability due to its potential for remote code execution on affected DrayTek Vigor2960 routers.
How do I fix CVE-2024-48074?
To remediate CVE-2024-48074, update the DrayTek Vigor2960 router firmware to the latest version that addresses this vulnerability.
What routers are affected by CVE-2024-48074?
CVE-2024-48074 affects the DrayTek Vigor2960 router running version 1.4.4.
What type of attack does CVE-2024-48074 enable?
CVE-2024-48074 allows attackers to execute arbitrary commands on the affected router, leading to potential unauthorized access.
Are there any workarounds for CVE-2024-48074?
Temporary mitigations for CVE-2024-48074 include restricting router access to trusted IP addresses until a firmware update can be applied.