peter bassill · operator
$ cve CVE-2024-12987 JSON

CVE-2024-12987 KEV

7.3
HIGH · CVSS 3.1 · EPSS 98.1% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-06-05.

Description

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

Scoring

CVSS7.3 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS98.08% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-77
On CISA KEVyes — remediate by 2025-06-05
Public exploitnone known
Published2024-12-27
Last modified2026-06-17

CISA KEV

NameDrayTek Vigor Routers OS Command Injection Vulnerability
Added2025-05-15
Due2025-06-05
Vendor / productDrayTek / Vigor Routers
Ransomware usenone reported

Affected (4)

VendorProduct
draytekvigor2960
draytekvigor2960 firmware
draytekvigor300b
draytekvigor300b firmware

References

→ the Explorer  ·  watch your stack  ·  NVD