CVE-2020-15415

Confirmed PUBLISHED

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via...

DrayTek · Vigor3900, Vigor2960, Vigor300B
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
9.8 Critical EPSS 84.6%

At a Glance

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

cisa nuclei_scanner python edge
CVE Published
Jun 30, 2020
Exploitation Reported
Sep 30, 2024
CVSS
9.8 Critical
EPSS
84.6%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
draytek
vigor3900_firmware

0 to < 1.5.1

Affected
draytek
vigor2960_firmware

0 to < 1.5.1

Affected
draytek
vigor300b_firmware

0 to < 1.5.1

Affected
n/a
n/a

n/a

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.