CRITICAL

CVE-2021-43118

CVSS v3

9.8

CRITICAL

EPSS Score

32.1%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.

Technical details

Published
3/29/2022

Frequently asked questions

What is CVE-2021-43118?

A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.

Is CVE-2021-43118 actively exploited?

Active exploitation of CVE-2021-43118 has not been confirmed. The EPSS score is 32.1%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-43118?

CVE-2021-43118 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2021-43118 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.