CVE List

CVE-2020-14993

Severe 9.8

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.

Published June 23, 2020.

Affected software

Get alerts for Draytek Vigor3900 Firmware

Reference links