Description
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.
References
Weaknesses
134c704f-9b21-4f2e-91b3-4a467353bcc0
Secondary
CWE-77
CVSS impact metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8 · Critical
Information
Source identifier
Vulnerability status
Analyzed
Published
2024-10-14T14:15:03.840Z
1 year agoLast modified
2025-04-10T12:37:33.973Z
11 months ago