CVE-2020-15415

draytek vigor3900_firmware, draytek vigor2960_firmware, draytek vigor300b_firmware

Published 30 Jun 2020 · updated 17 Jun 2026 · Analyzed

9.8 Critical · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 30 Sept 2024, with a remediation deadline of 21 Oct 2024 for US federal agencies.

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

References