First published: Mon Nov 04 2024(Updated: )
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DrayTek Vigor Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51249 has a high severity due to its ability to allow remote command execution.
To fix CVE-2024-51249, users should upgrade to a patched version of the Draytek Vigor3900 firmware.
CVE-2024-51249 can lead to unauthorized access and control over the affected device.
Users of the Draytek Vigor3900 running firmware version 1.5.1.3 are affected by CVE-2024-51249.
CVE-2024-51249 exploits the device by injecting malicious commands through the mainfunction.cgi script.