PT-2024-31277 · Draytek · Draytek Vigor3900
Jfkk
·
Published
2024-09-06
·
Updated
2024-09-11
·
CVE-2024-44845
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DrayTek Vigor3900 version 1.5.1.6
Description
The issue is an authenticated command injection vulnerability. It occurs via the
value parameter in the filter string function.Recommendations
For DrayTek Vigor3900 version 1.5.1.6, as a temporary workaround, consider restricting access to the
filter string function until a patch is available. Avoid using the value parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Draytek Vigor3900