Junglewise Threat Intelligence

CVE-2024-12987: DrayTek Vigor Routers OS Command Injection Vulnerability

CVE-2024-12987 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-05-15

Vendors: DrayTek.

Executive brief

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability in the Web Management Interface. The flaw exists within the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint where improper neutralization of the 'session' argument allows remote attackers to execute arbitrary commands.

Affected products

  • DrayTek Vigor2960 1.5.1.4
  • DrayTek Vigor300B 1.5.1.4
  • DrayTek Vigor3900 1.5.1.4

Timeline

  • 2025-05-14: disclosed: Public disclosure of the exploit and vulnerability details.
  • 2025-05-15: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
  • 2025-05-15: patched: Firmware version 1.5.1.5 released to address the issue.

Related threats