PT-2020-6382 · Draytek · Draytek Vigor3900+2
Published
2020-02-01
·
Updated
2025-12-11
·
CVE-2020-8515
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DrayTek Vigor3900 versions 1.4.4 Beta and earlier
DrayTek Vigor2960 versions 1.3.1 Beta and earlier
DrayTek Vigor300B versions 1.3.3 Beta, 1.4.2.1 Beta, and 1.4.4 Beta
Description
The issue is related to the WebUI interface of DrayTek Vigor routers, which allows remote code execution as root without authentication via shell metacharacters to the
cgi-bin/mainfunction.cgi URI. This can be exploited by an attacker to gain unauthorized access to the system. The estimated number of potentially affected devices worldwide is not specified, but it is reported that hundreds of organizations globally have been affected by attacks exploiting this issue. Real-world incidents involve the deployment of ransomware in the networks of affected organizations to gain access to account credentials.Recommendations
For DrayTek Vigor3900 versions 1.4.4 Beta and earlier, update to version 1.5.1 or later.
For DrayTek Vigor2960 versions 1.3.1 Beta and earlier, update to version 1.5.1 or later.
For DrayTek Vigor300B versions 1.3.3 Beta, 1.4.2.1 Beta, and 1.4.4 Beta, update to version 1.5.1 or later.
As a temporary workaround, consider restricting access to the
cgi-bin/mainfunction.cgi URI to minimize the risk of exploitation.Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Draytek Vigor2960
Draytek Vigor300B
Draytek Vigor3900