CVE-2024-51251: OS Command Injection
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51251?
CVE-2024-51251 has been classified with a severity rating that indicates high risk due to the potential for arbitrary command execution.
How do I fix CVE-2024-51251?
To fix CVE-2024-51251, update your Draytek Vigor3900 device to the latest firmware version that addresses this vulnerability.
What types of attacks can exploit CVE-2024-51251?
CVE-2024-51251 can be exploited through command injection attacks targeting the mainfunction.cgi script.
Which versions of Draytek Vigor3900 are affected by CVE-2024-51251?
CVE-2024-51251 specifically affects Draytek Vigor3900 running version 1.5.1.3.
What are the potential consequences of CVE-2024-51251 exploitation?
Exploitation of CVE-2024-51251 could allow attackers to execute arbitrary commands on the affected device, potentially leading to unauthorized access or control.