First published: Mon Oct 28 2024(Updated: )
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DrayTek Vigor |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-48074 is considered a critical vulnerability due to its potential for remote code execution on affected DrayTek Vigor2960 routers.
To remediate CVE-2024-48074, update the DrayTek Vigor2960 router firmware to the latest version that addresses this vulnerability.
CVE-2024-48074 affects the DrayTek Vigor2960 router running version 1.4.4.
CVE-2024-48074 allows attackers to execute arbitrary commands on the affected router, leading to potential unauthorized access.
Temporary mitigations for CVE-2024-48074 include restricting router access to trusted IP addresses until a firmware update can be applied.