Skip to content
COOEY

EXPOSURES › CVE-2024-12987

CVE-2024-12987

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-05-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-12987 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

DrayTek routers are vulnerable to OS command injection, currently being exploited in the wild, impacting network security and compliance posture.

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers have a command injection vulnerability in their web management interface, allowing attackers to execute arbitrary commands. DIB organizations using these routers face potential network compromise, data exfiltration, and non-compliance with CMMC/NIST 800-171. Immediate patching and network segmentation are required.

Shame score — The vulnerability's active exploitation and potential for widespread compromise demonstrate a significant security oversight by DrayTek.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.