CVE-2024-48074

HIGH EXPLOITED

Draytek Vigor2960 Firmware - OS Command Injection

Title source: rule
STIX 2.1

Description

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.

References (2)

Core 2

Scores

CVSS v3 8.0
EPSS 0.0021
EPSS Percentile 43.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

VulnCheck KEV 2025-08-22
CWE
CWE-78
Status published
Products (1)
draytek/vigor2960_firmware 1.4.4
Published Oct 28, 2024
Tracked Since Feb 18, 2026