Executive brief
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in the cvmcfgupload endpoint of mainfunction.cgi. Remote attackers can execute arbitrary commands via shell metacharacters in a filename when the text/x-python-script content type is used.
Affected products
- DrayTek Vigor3900 before 1.5.1
- DrayTek Vigor2960 before 1.5.1
- DrayTek Vigor300B before 1.5.1
Timeline
- 2020-06-30: disclosed: NVD Published Date
- 2024-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-09-30: exploited: Reported as exploited in the wild in CISA KEV catalog