CVE-2023-24229

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-03-15 18:15

Updated : 2024-07-16 14:15


NVD link : CVE-2023-24229

Mitre link : CVE-2023-24229

CVE.ORG link : CVE-2023-24229


JSON object : View

Products Affected

draytek

  • vigor2960_firmware
  • vigor2960
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')