CVE-2024-12987Active Exploitation(draytek / vigor2960)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for draytek vigor2960 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-06-05. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-77CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vigor2960
  • vigor2960_firmware
  • vigor300b
  • vigor300b_firmware

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 3 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-05-02); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
vigor2960vigor2960_firmwarevigor300bvigor300b_firmware

2 versions affected across 4 products

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-08: 1Mentions · 2026-04-08: 1Mentions · 2026-05-02: 2Mentions · 2026-10-02: 1PoC Mentioned / Linked · 2026-05-02: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-05-02: 2Technical Details · 2026-05-02: 103-0804-0805-0210-02
Signal classification2 categories
Active Exploitation
375.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-081
General1
2026-04-081
Active Exploitation1
2026-05-022
Active Exploitation2
Full discourse5 posts
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    The tweet presents a list of 25 CVEs identified by Team Cymru as currently being exploited in the wild, but it lacks detailed technical information, PoC, or patch guidance.

    070921.2K
    5.5K followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    CVE-2024-12987: OS command injection in DrayTek Vigor2960/300B/3900 via web interface file /cgi-bin/mainfunction.cgi/apmcfgupload; confirmed exploited and in CISA KEV.

    Post summary

    CVE-2024-12987 is an OS command‐injection flaw in DrayTek routers that has been confirmed exploited in the wild and listed in the CISA KEV.

    1000040
    152 followersView on X
  • NoHeartz@Noheartz1337
    General

    If this doesn't work, I'll be really pissed off 🗿... CVE-2021-46381 CVE-2022-0679 CVE-2023-1177 CVE-2024-12987 CVE-2025-47813 #NoHeartz #CVE #CommonVulnerabilitiesExposures #CyberNews #CyberAttack https://t.co/hrDFVeNHj0

    Post summary

    The tweet simply enumerates several CVE identifiers without mentioning any PoC, exploit code, active exploitation, patches, technical details, or false positive claims.

    00010200
    4 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: High CVE: CVE-2024-12987 Product: DrayTek / Vigor Routers Summary: VulnCheck reports real-world exploitation activity affecting DrayTek / Vigor Routers. Evidence: Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 12 Feb 2025 Source: https://vulncheck.com/ #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #DrayTek #VigorRouters #CVE_2024_12987 #ActiveExploitation #Exploit

    0000065
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    https://research.lyrie.ai/research/active-exploit-cve-2024-12987-vigor-routers #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The linked research indicates real‑world exploitation of CVE‑2024‑12987 on Vigor routers, though specific technical details and patch status remain undisclosed.

    0000028
    152 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWdraytekvigor2960---
OSdraytekvigor2960_firmware1.5.1.4--
HWdraytekvigor300b---
OSdraytekvigor300b_firmware1.5.1.4--

Explore more