In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.
This Cyber News was published on www.tenable.com. Publication date: Mon, 04 Nov 2024 17:26:03 +0000