EXPOSURES › CVE-2024-12987
CVE-2024-12987
HIGH ⌖ ON CISA KEV · EXPLOITEDDrayTek routers are vulnerable to OS command injection, currently being exploited in the wild, impacting network security and compliance posture.
DrayTek Vigor2960, Vigor300B, and Vigor3900 routers have a command injection vulnerability in their web management interface, allowing attackers to execute arbitrary commands. DIB organizations using these routers face potential network compromise, data exfiltration, and non-compliance with CMMC/NIST 800-171. Immediate patching and network segmentation are required.
Shame score — The vulnerability's active exploitation and potential for widespread compromise demonstrate a significant security oversight by DrayTek.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface.