CVE-2024-51249

CVSS 3.1 Score 8 of 10 (high)

Details

Published Nov 4, 2024
CWE ID 78

Summary

CVE-2024-51249 is a newly discovered vulnerability affecting the Draytek Vigor3900 device with firmware version 1.5.1.3. This issue grants attackers the ability to inject malicious commands into the mainfunction.cgi file and subsequently execute arbitrary commands on the system. The vulnerability is exploited by manipulating the input to the reboot function, which allows the attacker to bypass normal authentication procedures, potentially leading to serious security consequences. System administrators are strongly advised to update their Draytek Vigor3900 devices to the latest firmware version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • DrayTek Vigor 3900

Affected Vendors

  • DrayTek