CVE-2021-42911
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
Se presenta una vulnerabilidad de cadena de formato en DrayTek Vigor 2960 versiones anteriores a 1.5.1.3 incluyéndola, DrayTek Vigor 3900 versiones anteriores a 1.5.1.3 incluyéndola, y DrayTek Vigor 300B versiones anteriores a 1.5.1.3 incluyéndola, en el archivo mainfunction.cgi por medio de un mensaje HTTP diseñado que contiene una cadena de consulta malformada, lo que podría permitir a un usuario remoto malicioso ejecutar código arbitrario
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-10-25 CVE Reserved
- 2022-03-29 CVE Published
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- 2025-01-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-134: Use of Externally-Controlled Format String
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://gist.github.com/Cossack9989/e9c1c2d2e69b773ca4251acdd77f2835 | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Draytek Search vendor "Draytek" | Vigor2960 Firmware Search vendor "Draytek" for product "Vigor2960 Firmware" | <= 1.5.1.3 Search vendor "Draytek" for product "Vigor2960 Firmware" and version " <= 1.5.1.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2960 Search vendor "Draytek" for product "Vigor2960" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor3900 Firmware Search vendor "Draytek" for product "Vigor3900 Firmware" | <= 1.5.1.3 Search vendor "Draytek" for product "Vigor3900 Firmware" and version " <= 1.5.1.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor3900 Search vendor "Draytek" for product "Vigor3900" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor300b Firmware Search vendor "Draytek" for product "Vigor300b Firmware" | <= 1.5.1.3 Search vendor "Draytek" for product "Vigor300b Firmware" and version " <= 1.5.1.3" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor300b Search vendor "Draytek" for product "Vigor300b" | - | - |
Safe
|