Home

Description

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.

PUBLISHED Reserved 2024-10-08 | Published 2024-10-28 | Updated 2024-11-08 | Assigner mitre

References

github.com/Giles-one/Vigor2960Crack

gist.github.com/Giles-one/6425e97dcd1ec97a722a1e20da25fad7

cve.org (CVE-2024-48074)

nvd.nist.gov (CVE-2024-48074)

Download JSON