CVE-2024-12987mediumunder attackCWE-77CWE-78

CVE-2024-12987: medium-severity vulnerability in DrayTek Vigor2960

DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 6.9epss 98%
from disclosure to weapon
Published on NVDDec 27
CISA KEV+139d
exploitation probability
98%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 public exploit(s)
Action required by CISAfederal deadline: 2025-06-05

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

In short

A flaw in DrayTek router web management allows attackers to inject and execute arbitrary system commands by manipulating a session parameter in the configuration upload function, potentially giving complete control over the device.

Technical detail

OS command injection vulnerability in /cgi-bin/mainfunction.cgi/apmcfgupload endpoint of DrayTek Vigor2960 and Vigor300B (v1.5.1.4) via unsanitized session parameter; remote exploitation is possible without authentication requirements specified. Attack vector leverages CWE-77 (improper neutralization of special elements) and CWE-78 (OS command injection), allowing arbitrary command execution with device privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.