CVE-2024-12987
KEV PoC large1OS Command Injection in DrayTek Vigor2960/300B Web Interface
CISA: DrayTek Vigor Routers OS Command Injection Vulnerability
CVE-2024-12987 is an OS command injection flaw in the web management interface of DrayTek Vigor2960 and Vigor300B routers running firmware 1.5.1.4. An unauthenticated remote attacker triggers it by sending a crafted request to the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint with a manipulated 'session' parameter, which is passed to the underlying operating system without proper sanitization (CWE-77/CWE-78). Successful exploitation yields arbitrary operating-system command execution on the router, which can mean full device compromise and a foothold for pivoting into the protected network. Any organization running affected firmware on these models is exposed, especially sites where the management interface is reachable from the internet. Exploitation is confirmed in the wild: a public proof-of-concept is available, EPSS assigns a 98.1% probability of exploitation within 30 days (100th percentile), and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-15, requiring federal remediation under BOD 22-01.
What to do: Upgrade Vigor2960 and Vigor300B units from firmware 1.5.1.4 to version 1.5.1.5 or later. Until patched, restrict internet-facing access to the web management interface and review device logs for suspicious requests to /cgi-bin/mainfunction.cgi/apmcfgupload containing anomalous session parameters. Because the flaw is in CISA's KEV catalog, federal agencies must apply the vendor fix or applicable BOD 22-01 mitigations by the required deadline.
| DrayTek Vigor2960 firmware | 1.5.1.4 (fixed in 1.5.1.5) |
| DrayTek Vigor300B firmware | 1.5.1.4 (fixed in 1.5.1.5) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
- Affected
- DrayTek Vigor Routers
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- draytek
- Products
- vigor300b firmware, vigor2960 firmware
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X