CVE-2024-12987 | DrayTek Vigor2960/Vigor300B 1.5.1.4 Web Management Interface apmcfgupload session os command injection
A vulnerability classified as critical has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. This affects an unknown part of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection.
This vulnerability is traded as CVE-2024-12987. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.