CVE-2024-12987
CVSS 2.0 Score 7.5 of 10 (high)
Details
Summary
CVE-2024-12987 is a critical vulnerability affecting the Web Management Interface component of DrayTek Vigor2960 and Vigor300B devices running version 1.5.1.4. This issue lies within an unknown function of the /cgi-bin/mainfunction.cgi/apmcfgupload file and arises from the manipulation of the session argument. An attacker can exploit this flaw to inject os commands and potentially gain unauthorized system access. The exploit code has been made public, increasing the risk of attacks. Upgrading to version 1.5.1.5 is the recommended solution to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.