CVE-2024-48074

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.
Configurations

No configuration.

History

08 Nov 2024, 22:15

Type Values Removed Values Added
References
  • () https://gist.github.com/Giles-one/6425e97dcd1ec97a722a1e20da25fad7 -

29 Oct 2024, 19:35

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad RCE autorizada en el enrutador DrayTek Vigor2960 versión 1.4.4, donde un atacante puede colocar un comando malicioso en el parámetro de tabla de la función doPPPoE en la ruta cgi-bin/mainfunction.cgi y, finalmente, el comando es ejecutado por la función del sistema.
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0
CWE CWE-78

28 Oct 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-28 12:15

Updated : 2024-11-08 22:15


NVD link : CVE-2024-48074

Mitre link : CVE-2024-48074

CVE.ORG link : CVE-2024-48074


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')