PT-2024-30260 · Draytek · Draytek Vigor300B+2

N1Neman

·

Published

2024-08-21

·

Updated

2024-08-25

·

CVE-2024-43027

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DrayTek Vigor 3900 versions prior to v1.5.1.5 Beta DrayTek Vigor 2960 versions prior to v1.5.1.5 Beta DrayTek Vigor 300B versions prior to v1.5.1.5 Beta
Description A command injection vulnerability was discovered via the action parameter at the "cgi-bin/mainfunction.cgi" endpoint. This issue allows for command injection, potentially leading to unauthorized access or control.
Recommendations For DrayTek Vigor 3900 versions prior to v1.5.1.5 Beta, update to version v1.5.1.5 Beta or later. For DrayTek Vigor 2960 versions prior to v1.5.1.5 Beta, update to version v1.5.1.5 Beta or later. For DrayTek Vigor 300B versions prior to v1.5.1.5 Beta, update to version v1.5.1.5 Beta or later. As a temporary workaround, consider restricting access to the "cgi-bin/mainfunction.cgi" endpoint until a patch is available. Avoid using the action parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-43027

Affected Products

Draytek Vigor2960
Draytek Vigor300B
Draytek Vigor3900