DrayTek Vigor3900 security vulnerability allows attackers to execute arbitrary commands
CVE-2024-51257
8.8HIGH
What is CVE-2024-51257?
The DrayTek Vigor3900 version 1.5.1.3 has a command injection vulnerability that could allow an attacker to execute arbitrary commands on the device. By exploiting this flaw through the mainfunction.cgi interface and invoking the doCertificate function, unauthorized commands may be injected and executed, potentially compromising the security of the device and the networks it manages.