github.com
https://github.com/sadwwcxz/Vul CVE-2023-24229
HIGH
DrayTek vigor2960_firmware Improper Neutralization of Special Elements used in a Command ('Command Injection')
Record summary
CVE-2023-24229 has a selected CVSS score of 7.8 (high).
Description
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 18, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 16, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
vigor2960_firmwareBrowse DrayTek / vigor2960_firmwareDefault status: unknown | VulnCheck, CVE List | 1.5.1.4 | affected |
References
7nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-24229 web.archive.org
https://web.archive.org/web/20230315181013/https://github.com/sadwwcxz/Vul draytek.co.uk
https://www.draytek.co.uk/support/guides/kb-remotemanagement draytek.com
https://www.draytek.com/ draytek.com
https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 draytek.com
https://www.draytek.com/support/knowledge-base/5465