DrayTek Vigor3900 Firmware 1.5.1.3

CPE Details

DrayTek Vigor3900 Firmware 1.5.1.3
1.5.1.3
2022-04-05
15h06 +00:00
2022-04-06
12h05 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:o:draytek:vigor3900_firmware:1.5.1.3:*:*:*:*:*:*:*

Informations

Vendor

draytek

Product

vigor3900_firmware

Version

1.5.1.3

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2024-45882 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`
8
Haute
CVE-2024-45884 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`
8
Haute
CVE-2024-45885 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`
8
Haute
CVE-2024-45887 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`
8
Haute
CVE-2024-45888 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'
8
Haute
CVE-2024-45889 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`
8
Haute
CVE-2024-45890 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`
8
Haute
CVE-2024-45891 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`
8
Haute
CVE-2024-45893 2024-11-03 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`
8
Haute
CVE-2024-51246 2024-11-03 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.
8
Haute
CVE-2024-51249 2024-11-03 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.
8
Haute
CVE-2024-51251 2024-11-03 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.
8
Haute
CVE-2024-51253 2024-11-03 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.
8
Haute
CVE-2024-51244 2024-10-31 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
8.8
Haute
CVE-2024-51245 2024-10-31 23h00 +00:00 In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
8.8
Haute
CVE-2024-51247 2024-10-31 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
8.8
Haute
CVE-2024-51248 2024-10-31 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
8.8
Haute
CVE-2024-51252 2024-10-31 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
9.8
Critique
CVE-2024-51254 2024-10-30 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.
8.8
Haute
CVE-2024-51255 2024-10-30 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.
9.8
Critique
CVE-2024-51259 2024-10-30 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.
9.8
Critique
CVE-2024-51260 2024-10-30 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.
9.8
Critique
CVE-2024-51298 2024-10-30 00h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.
9.8
Critique
CVE-2024-51257 2024-10-29 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.
8.8
Haute
CVE-2024-51258 2024-10-29 23h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.
8.8
Haute
CVE-2024-51296 2024-10-29 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.
8.8
Haute
CVE-2024-51299 2024-10-29 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.
8.8
Haute
CVE-2024-51300 2024-10-29 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.
8.8
Haute
CVE-2024-51301 2024-10-29 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.
8.8
Haute
CVE-2024-51304 2024-10-29 23h00 +00:00 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.
8.8
Haute
CVE-2024-48153 2024-10-13 22h00 +00:00 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.
9.8
Critique
CVE-2021-43118 2022-03-29 17h37 +00:00 A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.
9.8
Critique
CVE-2021-42911 2022-03-29 17h30 +00:00 A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
9.8
Critique