boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-12987

DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    6.9   .9816   99.9   YES
AFFECTED
  Product    Versions   Fixed
  Vigor2960  1.5.1.4 –  —
  Vigor300B  1.5.1.4 –  —
TIMELINE
  Dec 27  Reserved by VulDB
  Dec 27  Published (CNA: VulDB)
  May 15  Added to CISA KEV, remediation due 2025-06-05
CWE-78, CWE-77 · CNA: VulDB · CVSS v4.0 · 8 references · KEV due June 5, 2025

Description

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
December 27, 2024ReservedReserved by VulDB
December 27, 2024PublishedPublished (CNA: VulDB)
May 15, 2025KEV ADDEDAdded to CISA KEV, remediation due 2025-06-05

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
DrayTekVigor2960—1.5.1.4—
DrayTekVigor300B—1.5.1.4—

Weaknesses

CWE-78 · CWE-77

References (8)

Related

Authoritative record: CVE-2024-12987 at cve.org

Vendors: draytek

Weaknesses: CWE-78 · CWE-77

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-12987 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.