draytek vigor3900_firmware CVE Vulnerabilities (48)

CVEs: 48 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting draytek vigor3900_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 120 of 48 CVEs
«« First « Prev Page 1 / 3 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2024-45893 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.` [email protected] 8.0 0.78% 2024-11-04 2025-04-10
CVE-2024-45891 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.` [email protected] 8.0 0.57% 2024-11-04 2025-04-10
CVE-2024-45890 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.` [email protected] 8.0 0.57% 2024-11-04 2025-04-10
CVE-2024-45889 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.` [email protected] 8.0 0.60% 2024-11-04 2025-04-10
CVE-2024-45888 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.' [email protected] 8.0 0.41% 2024-11-04 2025-04-10
CVE-2024-45887 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.` [email protected] 8.0 0.42% 2024-11-04 2025-04-10
CVE-2024-45885 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.` [email protected] 8.0 0.57% 2024-11-04 2025-04-10
CVE-2024-45884 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.` [email protected] 8.0 0.42% 2024-11-04 2025-04-10
CVE-2024-45882 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.` [email protected] 8.0 0.58% 2024-11-04 2025-04-10
CVE-2024-51253 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function. [email protected] 8.0 0.06% 2024-11-04 2025-04-10
CVE-2024-51251 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function. [email protected] 8.0 0.06% 2024-11-04 2025-04-10
CVE-2024-51249 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function. [email protected] 8.0 0.06% 2024-11-04 2025-04-11
CVE-2024-51246 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function. [email protected] 8.0 0.06% 2024-11-04 2025-04-11
CVE-2024-51252 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function. [email protected] 9.8 0.27% 2024-11-01 2024-11-05
CVE-2024-51248 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function. [email protected] 8.8 0.20% 2024-11-01 2024-11-05
CVE-2024-51247 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function. [email protected] 8.8 0.20% 2024-11-01 2024-11-05
CVE-2024-51245 In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function. [email protected] 8.8 0.20% 2024-11-01 2024-11-05
CVE-2024-51244 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function. [email protected] 8.8 0.20% 2024-11-01 2024-11-05
CVE-2024-51260 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function. [email protected] 9.8 0.24% 2024-10-31 2025-04-10
CVE-2024-51255 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function. [email protected] 9.8 0.20% 2024-10-31 2025-04-10
«« First « Prev Page 1 / 3 Next »
cvelogic Threat Intelligence