CVE-2023-24229

DrayTek Vigor2960 v1.5.1.4 was discovered to contain a command injection vulnerability via the mainfunction.cgi component.
References
Link Resource
https://github.com/sadwwcxz/Vul Exploit Third Party Advisory
https://www.draytek.com/ Not Applicable
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*

History

19 Mar 2023, 03:57

Type Values Removed Values Added
References (MISC) https://github.com/sadwwcxz/Vul - (MISC) https://github.com/sadwwcxz/Vul - Exploit, Third Party Advisory
References (MISC) https://www.draytek.com/ - (MISC) https://www.draytek.com/ - Not Applicable
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Draytek vigor2960 Firmware
Draytek
Draytek vigor2960
CWE CWE-77
CPE cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*

15 Mar 2023, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-15 18:15

Updated : 2023-03-19 03:57


NVD link : CVE-2023-24229

Mitre link : CVE-2023-24229


JSON object : View

Products Affected

draytek

  • vigor2960
  • vigor2960_firmware
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')