VendorsDrayTekvigor3900all versions
Vulnerabilities

DrayTek Vigor3900

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

48CVEs
CVE-2024-45885
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`
Published 2024-11-04 · Analyzed
8.0EPSS 0.013
CVE-2024-45891
DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`
Published 2024-11-04 · Analyzed
8.0EPSS 0.013
CVE-2024-43027
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.
Published 2024-08-21 · Analyzed
8.0EPSS 0.013
CVE-2024-46316
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.
Published 2024-10-09 · Analyzed
8.0EPSS 0.011
CVE-2024-51251
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.
Published 2024-11-04 · Analyzed
8.0EPSS 0.007
CVE-2024-51253
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.
Published 2024-11-04 · Analyzed
8.0EPSS 0.007
CVE-2024-51249
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.
Published 2024-11-04 · Analyzed
8.0EPSS 0.007
CVE-2024-51246
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.
Published 2024-11-04 · Analyzed
8.0EPSS 0.004
← Prev2 / 2