CVE-2024-45890: DrayTek VIGOR3900 Firmware

High severity, CVSS 8.0. EPSS: 2.1% chance of exploitation in the next 30 days.

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`

Affected products

  • DrayTek VIGOR3900 Firmware: version 1.5.1.3 only

Published 2024-11-04. Last modified 2026-06-17.