Skip to content

Known CVE

DrayTek Vigor - Command Injection

DrayTek Gateway devices (Vigor2960, Vigor300B, etc.) are vulnerable to command injection via the session parameter in the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint. An attacker can inject arbitrary commands and retrieve their output.

CVE-2024-12987

Critical2024CVSS 9.8CWE-78

cve2024 · draytek · rce · router · kev · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website