Site icon TheCyberThrone

CVE-2024-12987 affecting DrayTek Routers

Advertisements

CVE-2024-12987 is a critical security vulnerability identified in the DrayTek Vigor2960 and Vigor300B routers, specifically affecting firmware version 1.5.1.4. This vulnerability resides within the Web Management Interface, in the file path /cgi-bin/mainfunction.cgi/apmcfgupload.

Detailed Breakdown

1. Nature of the Vulnerability:
This vulnerability involves an OS Command Injection flaw. It is triggered by manipulating the session argument passed to the aforementioned file. The lack of proper input validation allows an attacker to inject and execute arbitrary OS commands on the affected device.

Advertisements

2. Impact:

3. Exploit Availability:

The exploit for this vulnerability has been publicly disclosed, which means that detailed information on how to exploit the vulnerability is available to potential attackers. This further amplifies the risk associated with the vulnerability.

4. Mitigation:

To remediate this issue, it is essential to upgrade the firmware to version 1.5.1.5, which has addressed this vulnerability. Users of affected devices should:

Advertisements

5. Recommendations:

Conclusion

Addressing CVE-2024-12987 promptly is crucial to maintaining the security of network infrastructures that use DrayTek Vigor2960 and Vigor300B routers. With approximately 10,000 devices globally affected, staying vigilant about firmware updates and employing best practices in network security can help mitigate the risks posed by such critical vulnerabilities.

Exit mobile version