CVE-2024-51257: Command Injection
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51257?
CVE-2024-51257 is considered highly severe as it allows attackers to execute arbitrary commands on DrayTek Vigor3900 devices.
How do I fix CVE-2024-51257?
To fix CVE-2024-51257, users should update their DrayTek Vigor3900 routers to the latest firmware version that addresses this vulnerability.
What devices are affected by CVE-2024-51257?
CVE-2024-51257 affects DrayTek Vigor3900 routers running firmware version 1.5.1.3.
What is the nature of the vulnerability in CVE-2024-51257?
The vulnerability in CVE-2024-51257 allows attackers to inject malicious commands into the mainfunction.cgi file.
Can CVE-2024-51257 lead to unauthorized access?
Yes, CVE-2024-51257 can lead to unauthorized access as it enables attackers to execute arbitrary commands on compromised devices.