PT-2020-6382 · Draytek · Draytek Vigor3900+2

Published

2020-02-01

·

Updated

2025-12-11

·

CVE-2020-8515

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions DrayTek Vigor3900 versions 1.4.4 Beta and earlier DrayTek Vigor2960 versions 1.3.1 Beta and earlier DrayTek Vigor300B versions 1.3.3 Beta, 1.4.2.1 Beta, and 1.4.4 Beta
Description The issue is related to the WebUI interface of DrayTek Vigor routers, which allows remote code execution as root without authentication via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This can be exploited by an attacker to gain unauthorized access to the system. The estimated number of potentially affected devices worldwide is not specified, but it is reported that hundreds of organizations globally have been affected by attacks exploiting this issue. Real-world incidents involve the deployment of ransomware in the networks of affected organizations to gain access to account credentials.
Recommendations For DrayTek Vigor3900 versions 1.4.4 Beta and earlier, update to version 1.5.1 or later. For DrayTek Vigor2960 versions 1.3.1 Beta and earlier, update to version 1.5.1 or later. For DrayTek Vigor300B versions 1.3.3 Beta, 1.4.2.1 Beta, and 1.4.4 Beta, update to version 1.5.1 or later. As a temporary workaround, consider restricting access to the cgi-bin/mainfunction.cgi URI to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04387
CVE-2020-8515

Affected Products

Draytek Vigor2960
Draytek Vigor300B
Draytek Vigor3900