PT-2020-12348 · Draytek · Vigor3900+2

Published

2020-03-26

·

Updated

2025-05-05

·

CVE-2020-10825

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Draytek Vigor3900 versions prior to 1.5.1 Draytek Vigor2960 versions prior to 1.5.1 Draytek Vigor300B versions prior to 1.5.1
Description A stack-based buffer overflow occurs in the /cgi-bin/activate.cgi endpoint while base64 decoding the ticket parameter, allowing remote attackers to achieve code execution via a remote HTTP request.
Recommendations For Draytek Vigor3900 versions prior to 1.5.1, update to version 1.5.1 or later to resolve the issue. For Draytek Vigor2960 versions prior to 1.5.1, update to version 1.5.1 or later to resolve the issue. For Draytek Vigor300B versions prior to 1.5.1, update to version 1.5.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the /cgi-bin/activate.cgi endpoint until a patch is available.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

CVE-2020-10825

Affected Products

Vigor2960
Vigor300B
Vigor3900