PT-2026-38912 · Draytek · Vigor2960

Published

2026-05-08

·

Updated

2026-05-09

·

CVE-2022-50994

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DrayTek Vigor 2960 versions prior to 1.5.1.4
Description An OS command injection issue exists in the CGI login handler. Unauthenticated remote attackers can execute arbitrary commands with web server privileges by injecting shell metacharacters into the formpassword parameter. This occurs because unsanitized input is passed to the otp check.sh script. Successful exploitation requires a valid username and for the target account to have MOTP (Mobile One-Time Password) authentication enabled.
Recommendations Update to version 1.5.1.4 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-50994

Affected Products

Vigor2960