CVE-2024-51298: DrayTek VIGOR3900 Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

Affected products

  • DrayTek VIGOR3900 Firmware: version 1.5.1.3 only

Published 2024-10-30. Last modified 2026-06-17.