CVE-2020-15415
draytek vigor3900_firmware, draytek vigor2960_firmware, draytek vigor300b_firmware
Published 30 Jun 2020 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 30 Sept 2024, with a remediation deadline of 21 Oct 2024 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
References
- github.com/CLP-team/Vigor-Commond-Injection · Exploit
- www.draytek.com/about/security-advisory · Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15415 · US Government Resource