CVE-2024-12987 KEV
7.3
HIGH · CVSS 3.1 · EPSS 98.1% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-06-05.
Description
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
Scoring
| CVSS | 7.3 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 98.08% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | yes — remediate by 2025-06-05 |
| Public exploit | none known |
| Published | 2024-12-27 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | DrayTek Vigor Routers OS Command Injection Vulnerability |
|---|---|
| Added | 2025-05-15 |
| Due | 2025-06-05 |
| Vendor / product | DrayTek / Vigor Routers |
| Ransomware use | none reported |
Affected (4)
| Vendor | Product |
|---|---|
| draytek | vigor2960 |
| draytek | vigor2960 firmware |
| draytek | vigor300b |
| draytek | vigor300b firmware |
References
- https://netsecfish.notion.site/Command-Injection-in-apmcfgupload-endpoint-for-DrayTek-Gateway-Devices-1676b683e67c8040b7f1f0ffe29ce18f?pvs=4
- https://vuldb.com/?ctiid.289380
- https://vuldb.com/?id.289380
- https://vuldb.com/?submit.468795
- https://fw.draytek.com.tw/Vigor2960/Firmware/v1.5.1.5/DrayTek_Vigor2960_V1.5.1.5_01release-note.pdf
- https://fw.draytek.com.tw/Vigor300B/Firmware/v1.5.1.5/DrayTek_Vigor300B_V1.5.1.5_01release-note.pdf
- https://fw.draytek.com.tw/Vigor3900/Firmware/v1.5.1.5/DrayTek_Vigor3900_V1.5.1.5_01release-note.pdf
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-12987
→ the Explorer · watch your stack · NVD