Attackers can inject malicious commands and execute arbitrary actions through mainfunction.cgi
CVE-2024-51298

9.8CRITICAL

Key Information:

Vendor
Draytek
Status
Vendor
CVE Published:
30 October 2024

Summary

In Draytek Vigor3900 version 1.5.1.3, a remote command injection vulnerability exists due to improper validation of input in the mainfunction.cgi script. An attacker can exploit this weakness by calling the doGRETunnel function, allowing them to inject and execute arbitrary commands on the server. This can lead to unauthorized access and further compromise of the affected system.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-51298 : Attackers can inject malicious commands and execute arbitrary actions through mainfunction.cgi | SecurityVulnerability.io