← Back

CVE-2020-8515

Published: Feb 1, 2020Modified: Nov 7, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

Affected (5)

3 products
Vigor2960 Firmware
Vigor300b Firmware
Vigor3900 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.3.1 beta
Running on/withPlatform Versions
Draytek
Vigor2960
All versions
Configuration B
3 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Draytek
Version 1.3.3 beta
Version 1.4.2.1 beta
Version 1.4.4 beta
Running on/withPlatform Versions
Draytek
Vigor300b
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.4.4 beta
Running on/withPlatform Versions
Draytek
Vigor3900
All versions

Timeline

No history available yet.