CVE-2020-15415
DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 October 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 84.48% probability · 100th percentile
- CISA KEV
- Listed 30 September 2024 · due 21 October 2024
- Weakness
- CWE-78
- Affected
- draytek/vigor3900 firmware · draytek/vigor2960 firmware · draytek/vigor300b firmware
- Source
- cve@mitre.org
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-remote-code-injection/execution-vulnerability-(cve-2020-14472) ; https://nvd.nist.gov/vuln/detail/CVE-2020-15415
References
- https://github.com/CLP-team/Vigor-Commond-InjectionExploit
- https://www.draytek.com/about/security-advisoryVendor Advisory
- https://github.com/CLP-team/Vigor-Commond-InjectionExploit
- https://www.draytek.com/about/security-advisoryVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15415US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.