CVE-2024-43027
EUVD-2024-4001821.08.2024, 16:15
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| draytek | vigor300b_firmware | 𝑥 < 1.5.1.5 |
| draytek | vigor2960_firmware | 𝑥 < 1.5.1.5 |
| draytek | vigor3900_firmware | 𝑥 < 1.5.1.5 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| draytek | vigor3900_firmware | 𝑥 < 1.5.1.5_Beta | ADP |
| draytek | vigor2960_firmware | 𝑥 < 1.5.1.5_Beta | ADP |
| draytek | vigor300b_firmware | 𝑥 < 1.5.1.5_Beta | ADP |