First published: Wed Oct 30 2024(Updated: )
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DrayTek Vigor Routers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-51257 is considered highly severe as it allows attackers to execute arbitrary commands on DrayTek Vigor3900 devices.
To fix CVE-2024-51257, users should update their DrayTek Vigor3900 routers to the latest firmware version that addresses this vulnerability.
CVE-2024-51257 affects DrayTek Vigor3900 routers running firmware version 1.5.1.3.
The vulnerability in CVE-2024-51257 allows attackers to inject malicious commands into the mainfunction.cgi file.
Yes, CVE-2024-51257 can lead to unauthorized access as it enables attackers to execute arbitrary commands on compromised devices.