Attackers can inject malicious commands and execute arbitrary actions through mainfunction.cgi
CVE-2024-51298
9.8CRITICAL
Summary
In Draytek Vigor3900 version 1.5.1.3, a remote command injection vulnerability exists due to improper validation of input in the mainfunction.cgi script. An attacker can exploit this weakness by calling the doGRETunnel function, allowing them to inject and execute arbitrary commands on the server. This can lead to unauthorized access and further compromise of the affected system.
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved