First published: Fri Nov 01 2024(Updated: )
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
DrayTek Vigor 3900 | =1.5.1.3 | |
DrayTek Vigor Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51252 has a high severity level due to the potential for remote code execution.
To fix CVE-2024-51252, upgrade the Draytek Vigor3900 firmware to a version that addresses this vulnerability.
CVE-2024-51252 allows attackers to inject malicious commands and execute arbitrary commands on the device.
CVE-2024-51252 specifically affects Draytek Vigor3900 firmware version 1.5.1.3.
CVE-2024-51252 can be exploited by unauthorized attackers who have network access to the vulnerable device.