7.8
CVSSv3

CVE-2023-24229

Published: 15/03/2023 Updated: 11/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Vulnerable Product Search on Vulmon Subscribe to Product

draytek vigor2960_firmware 1.5.1.4