VendorsDrayTekvigor3900_firmware1.5.1.6
Vulnerabilities

DrayTek Vigor3900 Firmware 1.4.4 Beta 1.5.1.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2024-44845
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.
Published 2024-09-06 · Analyzed
8.8EPSS 0.020
CVE-2024-44844
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.
Published 2024-09-06 · Analyzed
8.8EPSS 0.019
CVE-2024-46316
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.
Published 2024-10-09 · Analyzed
8.0EPSS 0.011