CVE-2024-12986
PoC largeUnauthenticated OS Command Injection in DrayTek Vigor2960/300B Web Interface
CVE-2024-12986 is an OS command injection flaw in the web management interface of DrayTek Vigor2960 and Vigor300B gateways running firmware 1.5.1.3 or 1.5.1.4. It is triggered by sending a crafted, unauthenticated HTTP request to the /cgi-bin/mainfunction.cgi/apmcfgupptim endpoint with a manipulated 'session' argument, which is passed into an OS command. A remote attacker with no privileges or user interaction gains the ability to execute arbitrary operating-system commands on the affected device. Any organization running these two DrayTek models on the affected firmware is exposed, particularly where the web management interface is reachable from untrusted networks. A public proof-of-concept has been disclosed, EPSS assigns a 32.8% probability of exploitation within 30 days (98th percentile), the flaw is not yet in CISA KEV, and there is no confirmed in-the-wild exploitation.
What to do: Upgrade Vigor2960 and Vigor300B firmware to version 1.5.1.5 or later. Until patched, restrict access to the web management interface (allow it only from trusted management networks and avoid WAN exposure), and check device firmware versions plus logs for unexpected requests to /cgi-bin/mainfunction.cgi/apmcfgupptim.
| draytek Vigor2960 firmware | 1.5.1.3 and 1.5.1.4 (fixed in 1.5.1.5) |
| draytek Vigor300B firmware | 1.5.1.3 and 1.5.1.4 (fixed in 1.5.1.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. The manipulation of the argument session leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
- Vendors
- draytek
- Products
- vigor300b firmware, vigor2960 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.