Junglewise Threat Intelligence

CVE-2020-8515: Multiple DrayTek Vigor Routers Web Management Page Vulnerability

CVE-2020-8515 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Vendors: DrayTek.

Executive brief

DrayTek Vigor2960, Vigor3900, and Vigor300B routers are vulnerable to unauthenticated remote code execution as root. The flaw exists in the cgi-bin/mainfunction.cgi URI due to improper neutralization of shell metacharacters.

Affected products

  • DrayTek Vigor2960 1.3.1_Beta
  • DrayTek Vigor3900 1.4.4_Beta
  • DrayTek Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, 1.4.4_Beta

Timeline

  • 2020-01-28: disclosed: Initial third-party disclosure via blog post
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2020-02-10: patched: Fixed in firmware version 1.5.1

Related threats