Executive brief
DrayTek Vigor2960, Vigor3900, and Vigor300B routers are vulnerable to unauthenticated remote code execution as root. The flaw exists in the cgi-bin/mainfunction.cgi URI due to improper neutralization of shell metacharacters.
Affected products
- DrayTek Vigor2960 1.3.1_Beta
- DrayTek Vigor3900 1.4.4_Beta
- DrayTek Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, 1.4.4_Beta
Timeline
- 2020-01-28: disclosed: Initial third-party disclosure via blog post
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2020-02-10: patched: Fixed in firmware version 1.5.1