LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2024-12987: DrayTek Vigor Routers OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 15, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 5, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2024-12987 to its Known Exploited Vulnerabilities catalog on May 15, 2025, with a federal patch deadline of Jun 5, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web…

CVE-2024-12987 is an OS command injection vulnerability affecting certain DrayTek Vigor routers. It exists in the web management interface and can allow an attacker who can reach that interface to run operating-system commands on the device. Because these routers often sit at network edges and handle traffic for many hosts, successful abuse can give an attacker a foothold for further movement, configuration changes, or traffic interception. Confirm exact impact and affected firmware against the vendor advisory.

CISA lists the issue against DrayTek Vigor2960, Vigor300B, and Vigor3900 models and directs organizations to apply vendor mitigations or discontinue use if mitigations are unavailable. Ransomware use is not documented for this CVE.

How it works

The weakness is classified as CWE-78 (OS Command Injection). In this class of flaw, user-controlled input reaches a system command interpreter without proper sanitization or parameterization. An attacker who can interact with the vulnerable endpoint can craft input that the device treats as part of a shell command, allowing arbitrary command execution under the privileges of the web-management process.

According to the CISA summary, the issue is tied to an unknown function in the file path /cgi-bin/mainfunction.cgi/apmcfgupload within the web management interface of the listed Vigor models. No further exploit mechanics are provided here; defenders should treat any unauthenticated or weakly authenticated access to that CGI endpoint as high risk and verify details in the vendor advisory rather than assuming specific payloads or authentication requirements.

Am I affected? How to find it in your systems

The vulnerability is reported against DrayTek Vigor2960, Vigor300B, and Vigor3900 routers. These devices commonly appear as edge or branch routers, VPN gateways, or small-to-medium business firewalls. Inventory steps:

Telemetry that may indicate probing or exploitation includes unusual POST or GET requests to /cgi-bin/mainfunction.cgi/apmcfgupload, unexpected process creation or shell activity on the router, sudden configuration changes, or outbound connections originating from the device itself. Correlate web-server logs (if retained) with firewall and NetFlow data. Confirm any indicators against the vendor advisory before treating them as definitive.

How to remediate

Patch first. Apply the mitigations or firmware updates supplied by DrayTek for the affected models, following the exact instructions in the vendor advisory. CISA’s required action is to apply those vendor mitigations, follow applicable BOD 22-01 guidance where cloud services are involved, or discontinue use of the product if mitigations are unavailable.

After updating:

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

If your data may have been exposed

Actively exploited edge-device vulnerabilities frequently lead to broader network compromise and data exposure. If these routers were reachable from untrusted networks and remained unpatched, treat any credentials, configuration data, or traffic that traversed them as potentially compromised. Rotate secrets, review logs for lateral movement, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to determine whether associated accounts appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDrayTek · Vigor Routers
WeaknessCWE-78
Added to CISA KEVMay 15, 2025
Federal patch deadlineJun 5, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities