Attackers can inject malicious commands and execute arbitrary actions through mainfunction.cgi
CVE-2024-51298
9.8CRITICAL
What is CVE-2024-51298?
In Draytek Vigor3900 version 1.5.1.3, a remote command injection vulnerability exists due to improper validation of input in the mainfunction.cgi script. An attacker can exploit this weakness by calling the doGRETunnel function, allowing them to inject and execute arbitrary commands on the server. This can lead to unauthorized access and further compromise of the affected system.