DrayTek Vigor3900 Security Vulnerability Allows Malicious Commands Execution
CVE-2024-51258
8.8HIGH
What is CVE-2024-51258?
A security flaw in DrayTek Vigor3900 version 1.5.1.3 allows an attacker to inject malicious commands through the 'mainfunction.cgi' interface, enabling the execution of arbitrary commands by utilizing the 'doSSLTunnel' function. This vulnerability poses significant risks, as it can lead to unauthorized access and control over the device, potentially compromising network integrity.