CVE-2023-24229: DrayTek VIGOR2960 Firmware
High severity, CVSS 7.8. EPSS: 6.7% chance of exploitation in the next 30 days.
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
- DrayTek VIGOR2960 Firmware: version 1.5.1.4 only
Published 2023-03-15. Last modified 2026-06-17.