← Back

CVE-2020-14993

nvd nist
Published: Jun 23, 2020Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.

Affected (3)

3 products
Vigor300b Firmware
Vigor2960 Firmware
Vigor3900 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.5.1.1
Running on/withPlatform Versions
Draytek
Vigor300b
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.5.1.1
Running on/withPlatform Versions
Draytek
Vigor2960
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.5.1.1
Running on/withPlatform Versions
Draytek
Vigor3900
All versions

Timeline

No history available yet.