Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2024-51252

Disclosure Date: November 01, 2024 (last updated November 06, 2024)
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
Attacker Value
Unknown

CVE-2024-51248

Disclosure Date: November 01, 2024 (last updated November 06, 2024)
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
Attacker Value
Unknown

CVE-2024-51247

Disclosure Date: November 01, 2024 (last updated November 06, 2024)
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
Attacker Value
Unknown

CVE-2024-51245

Disclosure Date: November 01, 2024 (last updated November 06, 2024)
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
Attacker Value
Unknown

CVE-2024-51244

Disclosure Date: November 01, 2024 (last updated November 06, 2024)
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
Attacker Value
Unknown

CVE-2021-43118

Disclosure Date: March 29, 2022 (last updated October 07, 2023)
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.