CVE-2024-41585

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.
Configurations

No configuration.

History

07 Oct 2024, 19:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.8
CWE CWE-78

04 Oct 2024, 13:50

Type Values Removed Values Added
Summary
  • (es) Los dispositivos DrayTek Vigor3910 hasta la versión 4.3.2.6 están afectados por una vulnerabilidad de inyección de comandos del sistema operativo que permite a un atacante aprovechar el binario recvCmd para escapar de la instancia emulada e inyectar comandos arbitrarios en la máquina host.

03 Oct 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-03 19:15

Updated : 2024-10-07 19:37


NVD link : CVE-2024-41585

Mitre link : CVE-2024-41585

CVE.ORG link : CVE-2024-41585


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')