PT-2023-9802 · Draytek · Draytek Vigor2960

Published

2023-03-15

·

Updated

2024-12-10

·

CVE-2023-24229

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DrayTek Vigor2960 version 1.5.1.4
Description The issue allows an authenticated attacker with network access to the web management interface to inject operating system commands via the parameter parameter in the mainfunction.cgi component. This can enable the execution of arbitrary commands. The vulnerability exists due to the lack of measures to neutralize special elements.
Recommendations For DrayTek Vigor2960 version 1.5.1.4, consider disabling access to the mainfunction.cgi component or restricting the use of the parameter parameter until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-11409
CVE-2023-24229

Affected Products

Draytek Vigor2960