Command Injection Vulnerability in DrayTek Vigor3900
CVE-2024-45888
Currently unrated
Summary
The DrayTek Vigor3900 running version 1.5.1.3 is susceptible to a command injection vulnerability. This occurs when an attacker manipulates the action
parameter within the cgi-bin/mainfunction.cgi interface, specifically when invoking the set_ap_map_config
function. Through this flaw, remote attackers may execute arbitrary commands on the affected device, potentially compromising network security and system integrity.
References
Timeline
Vulnerability published