9.8
CVSSv3

CVE-2020-10826

Published: 26/03/2020 Updated: 22/04/2022
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices prior to 1.5.1 allows remote malicious users to achieve command injection via a remote HTTP request in DEBUG mode.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

draytek vigor300b_firmware

draytek vigor3900_firmware

draytek vigor2960_firmware