Skip to content

Instantly share code, notes, and snippets.

@Giles-one
Created November 8, 2024 14:09
Show Gist options
  • Save Giles-one/6425e97dcd1ec97a722a1e20da25fad7 to your computer and use it in GitHub Desktop.
Save Giles-one/6425e97dcd1ec97a722a1e20da25fad7 to your computer and use it in GitHub Desktop.
The reference for CVE-2024-48074
[CVE ID]
CVE-2024-48074
[PRODUCT]
draytek - vigor2960
[FIRMWARE VERSION]
v1.4.4
[Vulnerability Type]
CWE-78 - os command injection
[Description]
An authorized RCE vulnerability exists in the Vigor2960 router, where an attacker can place a malicious command into the `table` parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function in the command splice string.
[Details]
https://github.com/Giles-one/Vigor2960Crack
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment