Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
draytek vulnerabilities and exploits
(subscribe to this query)
890
VMScore
CVE-2021-20125
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect 1.6.0-B3. An unauthenticated attacker could leverage this vulnerability to upload files to any location on the target operating sy...
Draytek Vigorconnect 1.6.0
578
VMScore
CVE-2020-19664
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
Draytek Vigor2960 Firmware
1 Github repository
668
VMScore
CVE-2020-15415
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
Draytek Vigor300b Firmware
668
VMScore
CVE-2020-14473
Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware prior to 1.5.1.1.
Draytek Vigor300b Firmware
Draytek Vigor2960 Firmware
Draytek Vigor3900 Firmware
1 Github repository
668
VMScore
CVE-2020-14472
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices prior to 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
Draytek Vigor300b Firmware
Draytek Vigor2960 Firmware
Draytek Vigor3900 Firmware
668
VMScore
CVE-2020-14993
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices prior to 1.5.1.1 allows remote malicious users to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Draytek Vigor300b Firmware
Draytek Vigor2960 Firmware
Draytek Vigor3900 Firmware
445
VMScore
CVE-2020-3932
A vulnerable SNMP in Draytek VigorAP910C cannot be disabled, which may cause information leakage.
Draytek Vigorap 910c Firmware 1.3.1
668
VMScore
CVE-2020-10823
A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve code execution via a remote HTTP request (issue 1 of 3).
Draytek Vigor300b Firmware
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
890
VMScore
CVE-2020-10826
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve command injection via a remote HTTP request in DEBUG mode.
Draytek Vigor300b Firmware
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
668
VMScore
CVE-2020-10827
A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve code execution via a remote HTTP request.
Draytek Vigor300b Firmware
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »