Executive brief
DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability in the Web Management Interface. The flaw exists within the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint where improper neutralization of the 'session' argument allows remote attackers to execute arbitrary commands.
Affected products
- DrayTek Vigor2960 1.5.1.4
- DrayTek Vigor300B 1.5.1.4
- DrayTek Vigor3900 1.5.1.4
Timeline
- 2025-05-14: disclosed: Public disclosure of the exploit and vulnerability details.
- 2025-05-15: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.
- 2025-05-15: patched: Firmware version 1.5.1.5 released to address the issue.