Draytek
Draytek Vigor3900 Firmware: vulnerabilidades y CVE
Draytek Vigor3900 Firmware tiene 48 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 19 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE48
Últimos 12 meses0
Críticas19
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2020-15415 | Crítica (9.8) | 84% | ⚠ Explotación activa | 30 jun 2020 | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content… |
| CVE-2020-8515 | Crítica (9.8) | 100% | ⚠ Explotación activa | 1 feb 2020 | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-45893 | Alta (8) | 1.6% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.` |
| CVE-2024-45891 | Alta (8) | 1.3% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.` |
| CVE-2024-45890 | Alta (8) | 2.1% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.` |
| CVE-2024-45889 | Alta (8) | 1.6% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.` |
| CVE-2024-45888 | Alta (8) | 2.0% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.' |
| CVE-2024-45887 | Alta (8) | 2.1% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.` |
| CVE-2024-45885 | Alta (8) | 1.3% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.` |
| CVE-2024-45884 | Alta (8) | 2.1% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.` |
| CVE-2024-45882 | Alta (8) | 1.6% | — | 4 nov 2024 | DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.` |
| CVE-2024-51253 | Alta (8) | 0.69% | — | 4 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function. |
| CVE-2024-51251 | Alta (8) | 0.72% | — | 4 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function. |
| CVE-2024-51249 | Alta (8) | 0.69% | — | 4 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function. |
| CVE-2024-51246 | Alta (8) | 0.43% | — | 4 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function. |
| CVE-2024-51252 | Crítica (9.8) | 0.81% | — | 1 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function. |
| CVE-2024-51248 | Alta (8.8) | 0.81% | — | 1 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function. |
| CVE-2024-51247 | Alta (8.8) | 0.81% | — | 1 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function. |
| CVE-2024-51245 | Alta (8.8) | 0.81% | — | 1 nov 2024 | In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function. |
| CVE-2024-51244 | Alta (8.8) | 0.81% | — | 1 nov 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function. |
| CVE-2024-51260 | Crítica (9.8) | 0.62% | — | 31 oct 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function. |
| CVE-2024-51255 | Crítica (9.8) | 0.39% | — | 31 oct 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function. |
| CVE-2024-51259 | Crítica (9.8) | 0.35% | — | 31 oct 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function. |
| CVE-2024-51254 | Alta (8.8) | 0.43% | — | 31 oct 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function. |
| CVE-2024-51258 | Alta (8.8) | 0.56% | — | 30 oct 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function. |
| CVE-2024-51301 | Alta (8.8) | 0.61% | — | 30 oct 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function. |
| CVE-2024-51300 | Alta (8.8) | 0.61% | — | 30 oct 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function. |
| CVE-2024-51299 | Alta (8.8) | 0.61% | — | 30 oct 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function. |
| CVE-2024-51298 | Crítica (9.8) | 0.62% | — | 30 oct 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function. |
| CVE-2024-51296 | Alta (8.8) | 0.61% | — | 30 oct 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function. |
| CVE-2024-51257 | Alta (8.8) | 0.39% | — | 30 oct 2024 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function. |
| CVE-2024-51304 | Alta (8.8) | 0.61% | — | 30 oct 2024 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.