Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
draytek vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2020-14473
Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware prior to 1.5.1.1.
Draytek Vigor300b Firmware
Draytek Vigor2960 Firmware
Draytek Vigor3900 Firmware
1 Github repository
7.5
CVSSv2
CVE-2021-42911
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user exec...
Draytek Vigor2960 Firmware
Draytek Vigor3900 Firmware
Draytek Vigor300b Firmware
7.5
CVSSv2
CVE-2020-15415
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
Draytek Vigor300b Firmware
7.5
CVSSv2
CVE-2020-10824
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve code execution via a remote HTTP request (issue 2 of 3).
Draytek Vigor300b Firmware
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
10
CVSSv2
CVE-2020-10826
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve command injection via a remote HTTP request in DEBUG mode.
Draytek Vigor300b Firmware
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
7.5
CVSSv2
CVE-2020-10828
A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve code execution via a remote HTTP request.
Draytek Vigor300b Firmware
Draytek Vigor3900 Firmware
Draytek Vigor2960 Firmware
7.5
CVSSv2
CVE-2021-43118
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary co...
Draytek Vigor2960 Firmware 1.5.1.3
Draytek Vigor3900 Firmware 1.5.1.3
Draytek Vigor300b Firmware 1.5.1.3
NA
CVE-2023-31447
user_login.cgi on Draytek Vigor2620 devices prior to 3.9.8.4 (and on all versions of Vigor2925 devices) allows malicious users to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
Draytek Vigor2620 Firmware
Draytek Vigor2625 Firmware
6.8
CVSSv2
CVE-2013-5703
The DrayTek Vigor 2700 router 2.8.3 allows remote malicious users to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.
Draytek Vigor 2700 Router Firmware 2.8.3
Draytek Vigor 2700 Router -
NA
CVE-2023-6265
** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files....
Draytek Vigor2960 Firmware 1.5.1.4
Draytek Vigor2960 Firmware 1.5.1.5
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »