CVE-2024-45889: DrayTek VIGOR3900 Firmware

High severity, CVSS 8.0. EPSS: 1.6% chance of exploitation in the next 30 days.

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`

Affected products

  • DrayTek VIGOR3900 Firmware: version 1.5.1.3 only

Published 2024-11-04. Last modified 2026-06-17.