Junglewise Threat Intelligence

CVE-2020-15415: DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

CVE-2020-15415 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-09-30

Vendors: DrayTek.

Executive brief

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in the cvmcfgupload endpoint of mainfunction.cgi. Remote attackers can execute arbitrary commands via shell metacharacters in a filename when the text/x-python-script content type is used.

Affected products

  • DrayTek Vigor3900 before 1.5.1
  • DrayTek Vigor2960 before 1.5.1
  • DrayTek Vigor300B before 1.5.1

Timeline

  • 2020-06-30: disclosed: NVD Published Date
  • 2024-09-30: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-09-30: exploited: Reported as exploited in the wild in CISA KEV catalog

Related threats