CVE-2020-15415: DrayTek Multiple Vigor Routers
EPSS84.4%No. 562 of 1739 in KEV
CVE year2020~4 yrs before listing
Same vendor in KEV5
Same product2
| Field | Value |
|---|---|
| Vendor | DrayTek |
| Product | Multiple Vigor Routers |
| Name | DrayTek Multiple Vigor Routers OS Command Injection Vulnerability |
| Added to KEV | 2024-09-30 |
| US federal due date | 2024-10-21 |
| Ransomware use | Unknown |
| CWE | CWE-78 |
CISA description
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.
Other entries for this product
| CVE | Vendor / product | Added | EPSS | Ransomware |
|---|---|---|---|---|
| CVE-2020-8515 | DrayTek Multiple Vigor Routers | 2021-11-03 | 99.9% | Unknown |
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A DrayTek Multiple Vigor Routers vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2024-09-30.