CVE-2023-24229
43Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 7.8epss 6.7%
from disclosure to weapon
Published on NVDMar 15
VulnCheck+553d
exploitation probability
6.7%top 6% of all CVEs
observed exploitation
yesVulnCheck
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/aReferences
https://github.com/sadwwcxz/Vulhttps://web.archive.org/web/20230315181013/https://github.com/sadwwcxz/Vulhttps://www.draytek.com/https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960https://www.draytek.com/support/knowledge-base/5465https://www.draytek.co.uk/support/guides/kb-remotemanagement