High severity8.0NVD Advisory· Published Oct 28, 2024· Updated Jun 17, 2026
CVE-2024-48074
CVE-2024-48074
Description
An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- DrayTek/Vigor2960 routerdescription
- cpe:2.3:o:draytek:vigor2960_firmware:1.4.4:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- gist.github.com/Giles-one/6425e97dcd1ec97a722a1e20da25fad7nvdThird Party Advisory
News mentions
0No linked articles in our index yet.