Vulnerability Description
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Draytek | Vigor300B Firmware | < 1.5.1.5 |
| Draytek | Vigor300B | - |
| Draytek | Vigor2960 Firmware | < 1.5.1.5 |
| Draytek | Vigor2960 | - |
| Draytek | Vigor3900 Firmware | < 1.5.1.5 |
| Draytek | Vigor3900 | - |
Related Weaknesses (CWE)
References
- https://github.com/N1nEmAn/wp/blob/main/V3900.mdExploitThird Party Advisory
FAQ
What is CVE-2024-43027?
CVE-2024-43027 is a vulnerability with a CVSS score of 8.0 (HIGH). DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action...
How severe is CVE-2024-43027?
CVE-2024-43027 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-43027?
Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigor300B Firmware, Draytek Vigor300B, Draytek Vigor2960 Firmware, Draytek Vigor2960, Draytek Vigor3900 Firmware.