CVE-2020-10826: Command Injection
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10826?
CVE-2020-10826 is a vulnerability that allows remote attackers to achieve command injection on Draytek Vigor3900, Vigor2960, and Vigor300B devices before firmware version 1.5.1 via a remote HTTP request in DEBUG mode.
How severe is CVE-2020-10826?
CVE-2020-10826 has a severity value of 9.8, which is considered critical.
How can the CVE-2020-10826 vulnerability be exploited?
The CVE-2020-10826 vulnerability can be exploited by sending a remote HTTP request in DEBUG mode to the /cgi-bin/activate.cgi endpoint on affected Draytek Vigor3900, Vigor2960, and Vigor300B devices before firmware version 1.5.1.
Which devices are affected by CVE-2020-10826?
CVE-2020-10826 affects Draytek Vigor3900, Vigor2960, and Vigor300B devices before firmware version 1.5.1.
Is there a fix for CVE-2020-10826?
Yes, the fix for CVE-2020-10826 is to update the firmware on the affected Draytek Vigor3900, Vigor2960, and Vigor300B devices to version 1.5.1 or newer.