CVE-2024-12986

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 27, 2024
Updated: Dec 30, 2024
CWE ID 78
CWE ID 77

Summary

CVE-2024-12986 is a critical vulnerability affecting DrayTek Vigor2960 and Vigor300B devices running on versions 1.5.1.3 and 1.5.1.4. This issue lies in the processing of the /cgi-bin/mainfunction.cgi/apmcfgupptim file within the Web Management Interface. An attacker can manipulate the session argument to inject operating system commands. The exploit can be launched remotely, and the vulnerability has been made public. To mitigate this risk, users are advised to upgrade to the latest version, 1.5.1.5.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DrayTek Vigor2960
  • DrayTek Vigor 300B

Affected Vendors

  • DrayTek