CVE-2024-12987: medium-severity vulnerability in DrayTek Vigor2960
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
A flaw in DrayTek router web management allows attackers to inject and execute arbitrary system commands by manipulating a session parameter in the configuration upload function, potentially giving complete control over the device.
OS command injection vulnerability in /cgi-bin/mainfunction.cgi/apmcfgupload endpoint of DrayTek Vigor2960 and Vigor300B (v1.5.1.4) via unsanitized session parameter; remote exploitation is possible without authentication requirements specified. Attack vector leverages CWE-77 (improper neutralization of special elements) and CWE-78 (OS command injection), allowing arbitrary command execution with device privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.