PT-2023-9804 · Draytek · Draytek Vigor2960

Tmotfl

·

Published

2023-02-24

·

Updated

2024-08-02

·

CVE-2023-1009

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions DrayTek Vigor 2960 versions 1.5.1.4 through 1.5.1.5
Description A critical vulnerability has been found in the Web Management Interface of DrayTek Vigor 2960. The issue is related to the function sub 1DF14 of the file /cgi-bin/mainfunction.cgi. The manipulation of the argument option with the input /../etc/passwd- leads to path traversal. This allows an attacker to gain unauthorized access to confidential system files. The attack can be launched remotely. The exploit has been disclosed to the public.
Recommendations For DrayTek Vigor 2960 versions 1.5.1.4 through 1.5.1.5, as a temporary workaround, consider disabling the sub 1DF14 function until a patch is available. Restrict access to the /cgi-bin/mainfunction.cgi file to minimize the risk of exploitation. Avoid using the option argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2024-11415
CVE-2023-1009

Affected Products

Draytek Vigor2960