← Back

CVE-2024-41585

nvd nist
Published: Oct 3, 2024Modified: Apr 10, 2025

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.

Affected (1)

1 product
Vigor3910 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 4.3.2.6
Running on/withPlatform Versions
Draytek
Vigor3910
All versions

References (2)

Timeline

No history available yet.