📦 Vigor3900 Firmware

by Draytek

🔍 What is Vigor3900 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51252

CRITICAL CVSS 9.8 Nov 1, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi restore function. Attackers can gain ful...

CVE-2024-51255

CRITICAL CVSS 9.8 Oct 31, 2024

CVE-2024-51255 is a command injection vulnerability in DrayTek Vigor3900 routers that allows attackers to execute arbitrary commands via the mainfunction.cgi script. Attackers can exploit this by inje...

CVE-2024-51259

CRITICAL CVSS 9.8 Oct 31, 2024

This vulnerability allows remote attackers to execute arbitrary commands on DrayTek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi endpoint. Attackers can achieve full sys...

CVE-2024-51298

CRITICAL CVSS 9.8 Oct 30, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi endpoint. Attackers can exploit this to ...

CVE-2021-42911

CRITICAL CVSS 9.8 Mar 29, 2022

This is a critical format string vulnerability in DrayTek router firmware that allows remote attackers to execute arbitrary code by sending specially crafted HTTP messages. Attackers can potentially g...

CVE-2024-45887

HIGH CVSS 8.0 Nov 4, 2024

DrayTek Vigor3900 routers running firmware version 1.5.1.3 contain a post-authentication command injection vulnerability in the OpenVPN configuration handler. This allows authenticated attackers to ex...

CVE-2024-45889

HIGH CVSS 8.0 Nov 4, 2024

DrayTek Vigor3900 routers version 1.5.1.3 contain a post-authentication command injection vulnerability in the mainfunction.cgi endpoint. Attackers with valid credentials can execute arbitrary command...

CVE-2024-45891

HIGH CVSS 8.0 Nov 4, 2024

DrayTek Vigor3900 firmware version 1.5.1.3 contains a post-authentication command injection vulnerability in the delete_wlan_profile function. An attacker with valid administrator credentials can exec...

CVE-2024-45884

HIGH CVSS 8.0 Nov 4, 2024

DrayTek Vigor3900 firmware version 1.5.1.3 contains a post-authentication command injection vulnerability in the mainfunction.cgi endpoint. An attacker with valid credentials can execute arbitrary com...

CVE-2024-51249

HIGH CVSS 8.0 Nov 4, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi endpoint and calling the reboot function...

CVE-2024-51253

HIGH CVSS 8.0 Nov 4, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi component. Attackers can exploit this by...

CVE-2024-51244

HIGH CVSS 8.8 Nov 1, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi component. Attackers can exploit this th...

CVE-2024-51247

HIGH CVSS 8.8 Nov 1, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi endpoint. Attackers can achieve remote c...

CVE-2024-51258

HIGH CVSS 8.8 Oct 30, 2024

This vulnerability allows remote attackers to execute arbitrary commands on DrayTek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi script. Attackers can exploit this by ca...

CVE-2024-51257

HIGH CVSS 8.8 Oct 30, 2024

This vulnerability allows attackers to inject malicious commands into the mainfunction.cgi component of DrayTek Vigor3900 routers by exploiting the doCertificate function, leading to arbitrary command...

CVE-2024-51300

HIGH CVSS 8.8 Oct 30, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi endpoint. Attackers can achieve remote c...

CVE-2024-51304

HIGH CVSS 8.8 Oct 30, 2024

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfunction.cgi component. Attackers can exploit imprope...

CVE-2024-43027

HIGH CVSS 8.0 Aug 21, 2024

This CVE describes a command injection vulnerability in DrayTek router firmware that allows attackers to execute arbitrary commands on affected devices. Attackers can exploit this by sending specially...