CVE-2020-15415
קריטית 9.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 85% (אחוזון 100) נכון ל-24/7/2026
- CWE
- CWE-78
מוצרים מושפעים
draytek: vigor3900 firmware; draytek: vigor3900; draytek: vigor2960 firmware; draytek: vigor2960; draytek: vigor300b firmware; draytek: vigor300b
קישורים
- https://www.draytek.com/about/security-advisory Vendor Advisory
- https://www.draytek.com/about/security-advisory Vendor Advisory
- https://github.com/CLP-team/Vigor-Commond-Injection Exploit
- https://github.com/CLP-team/Vigor-Commond-Injection Exploit
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… US Government Resource