📦

vigor3900

Vendor: draytek

Actively Exploited 2 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 41 Remote Access
Total CVEs 59 Total Indexed
Avg. EPSS 7.54% Exploit Prob.
Latest CVE CVE-2024-45893 Nov 04

Security Vulnerability Index

Page 3 / 6
9.8 CVSS

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.

EPSS: 0.34%
8.8 CVSS

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.

EPSS: 0.41%
8.8 CVSS

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.

EPSS: 0.54%
8.8 CVSS

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.

EPSS: 0.60%
8.8 CVSS

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.

EPSS: 0.60%
8.8 CVSS

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.

EPSS: 0.60%
9.8 CVSS

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

EPSS: 0.60%
8.8 CVSS

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.

EPSS: 0.60%
8.8 CVSS

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.

EPSS: 0.37%
8.8 CVSS

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.

EPSS: 0.60%