Loading
DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message.
Use CWE-78, Draytek vendor hub and Vigor3900 Firmware product page to widen CVE-2024-46316 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-45893, CVE-2024-45891 and CVE-2024-45890 for nearby disclosures in the same product family.