CVE-2024-12987

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Dec 27, 2024
CWE ID 78
CWE ID 77

Summary

CVE-2024-12987 is a critical vulnerability affecting the Web Management Interface component of DrayTek Vigor2960 and Vigor300B devices running version 1.5.1.4. This issue lies within an unknown function of the /cgi-bin/mainfunction.cgi/apmcfgupload file and arises from the manipulation of the session argument. An attacker can exploit this flaw to inject os commands and potentially gain unauthorized system access. The exploit code has been made public, increasing the risk of attacks. Upgrading to version 1.5.1.5 is the recommended solution to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share