CVE-2020-14993
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.33%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.33% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- draytek/vigor300b firmware · draytek/vigor2960 firmware · draytek/vigor3900 firmware
- Source
- cve@mitre.org
References
- https://github.com/dexterone/Vigor-pocExploit, Third Party Advisory
- https://www.draytek.com/about/security-advisoryVendor Advisory
- https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-stack-based-buffer-overflow-vulnerability-%28cve-2020-14473%29
- https://github.com/dexterone/Vigor-pocExploit, Third Party Advisory
- https://www.draytek.com/about/security-advisoryVendor Advisory
- https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-stack-based-buffer-overflow-vulnerability-%28cve-2020-14473%29
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.