CVE-2024-48153: DrayTek VIGOR3900 Firmware
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.
Affected products
- DrayTek VIGOR3900 Firmware: version 1.5.1.3 only
Published 2024-10-14. Last modified 2026-06-17.