← back
CVE-2024-48074highobserved exploitationCWE-78

CVE-2024-48074

43Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 8epss 0.7%
from disclosure to weapon
Published on NVDOct 28
VulnCheck+298d
exploitation probability
0.7%top 50% of all CVEs
observed exploitation
yesVulnCheck
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a