ZeroHour

CVE-2023-47254

PoC
CVSS 3.1
9.8 critical
EPSS
2%p82
Published
()
Modified
Description

An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.

Vendors
draytek
Products
vigor167 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.