Exploited Vulnerabilities Daily
🌐 English

Home › DrayTek

CVE-2020-15415: DrayTek Multiple Vigor Routers

EPSS84.4%No. 562 of 1739 in KEV
CVE year2020~4 yrs before listing
Same vendor in KEV5
Same product2
FieldValue
VendorDrayTek
ProductMultiple Vigor Routers
NameDrayTek Multiple Vigor Routers OS Command Injection Vulnerability
Added to KEV2024-09-30
US federal due date2024-10-21
Ransomware useUnknown
CWECWE-78

CISA description

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.

Other entries for this product

CVEVendor / productAddedEPSSRansomware
CVE-2020-8515DrayTek Multiple Vigor Routers2021-11-0399.9%Unknown

NVD — CVE-2020-15415

Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page

A DrayTek Multiple Vigor Routers vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-30.