CVE-2020-10827: Buffer Overflow
Published Mar 26, 2020
·Updated
A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.
Affected Software
12 affected components
DrayTek Vigor300b Firmware<1.5.1
DrayTek Vigor300B
DrayTek Vigor3900 Firmware<1.5.1
DrayTek Vigor3900
DrayTek Vigor2960 Firmware<1.5.1
DrayTek Vigor2960
All of the following
DrayTek Vigor300b Firmware<1.5.1
DrayTek Vigor300B
All of the following
DrayTek Vigor3900 Firmware<1.5.1
DrayTek Vigor3900
All of the following
DrayTek Vigor2960 Firmware<1.5.1
DrayTek Vigor2960
Event History
Mar 26, 2020
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-10827.
2
Which devices are affected by this vulnerability?
Draytek Vigor3900, Vigor2960, and Vigor300B devices before version 1.5.1 are affected by this vulnerability.
3
How can remote attackers exploit this vulnerability?
Remote attackers can achieve code execution by sending a remote HTTP request to the affected devices.
4
What is the severity rating of this vulnerability?
The severity rating of this vulnerability is critical, with a CVSS score of 9.8.
5
Is there a fix available for this vulnerability?
Yes, a fix is available for this vulnerability in version 1.5.1 of the firmware for the affected devices.