S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated May 22, 2025

CVE-2024-12987 Scanner

CVE-2024-12987 Scanner - Command Injection vulnerability in DrayTek Vigor

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2024-12987
6.9
CVSSmedium
Exploitable remotely over the internet · no authentication required.

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Vigor2960by DrayTek
1.5.1.4
Vigor300Bby DrayTek
1.5.1.4
Updated Aug 19, 2026View on NVD →
Detail

DrayTek Vigor is a series of networking devices primarily used in small to medium-sized business environments. Known for their reliability, these devices offer functions such as routing, VPN, and network management. Network administrators use these devices to maintain secure and efficient network connections. The DrayTek Vigor devices, such as Vigor2960 and Vigor300B, provide vital networking functions and are integrated into various IT infrastructures. They are popular choices for organizations in need of stable and secure network operational capabilities. These devices' wide usage makes them frequent targets for security researchers and, unfortunately, cyber attackers.

Command Injection is a critical vulnerability that allows attackers to execute arbitrary system commands on a host server using vulnerable applications. In the context of DrayTek Vigor devices, this vulnerability emerges within the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint. Attackers leverage the session parameter to inject malicious commands that the host system could execute. This vulnerability allows attackers to seize control of the device, potentially compromising network traffic or accessing sensitive data. Given its critical nature, it is crucial to address Command Injection vulnerabilities promptly to protect the integrity of the network.

The technical details of the Command Injection vulnerability involve manipulating the session parameter in the HTTP requests sent to the DrayTek Vigor's /cgi-bin/mainfunction.cgi/apmcfgupload endpoint. Malicious actors can craft requests to inject and execute commands by utilizing specific character sequences and escape characters. The vulnerability stems from improper handling and sanitation of inputs by the network device's software, allowing injected commands to bypass security controls. It is tested by sending tailor-made requests to see if the vulnerable endpoint executes these injected commands.

Exploiting this Command Injection vulnerability could lead to severe consequences, including unauthorized access to the device, data breaches, and network disruptions. Potential effects encompass the execution of arbitrary commands, which may allow attackers to capture sensitive information, alter device configurations, or create persistent back doors for future access. Compromised devices might become part of a larger botnet, posing risks beyond the immediate network of the affected organization. If left unaddressed, the vulnerability can significantly weaken the network's security posture, facilitating further attacks.

REFERENCES

Solution Advice
  • Update the DrayTek device firmware to the latest version available.
  • Implement network segmentation to limit access to the device management interface.
  • Regularly audit and monitor network access logs for suspicious activities.
  • Configure proper input validation mechanisms on vulnerable endpoints.
  • Restrict access to critical device functionalities with robust authentication controls.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.