9.8
CVSSv3

CVE-2023-31447

Published: 21/08/2023 Updated: 30/08/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

user_login.cgi on Draytek Vigor2620 devices prior to 3.9.8.4 (and on all versions of Vigor2925 devices) allows malicious users to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.

Vulnerable Product Search on Vulmon Subscribe to Product

draytek vigor2620_firmware

draytek vigor2625_firmware