CVE-2020-14472: Command Injection
Published Jun 24, 2020
·Updated
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
Affected Software
6 affected components
DrayTek Vigor300b Firmware<1.5.1.1
DrayTek Vigor300B
DrayTek Vigor2960 Firmware<1.5.1.1
DrayTek Vigor2960
DrayTek Vigor3900 Firmware<1.5.1.1
DrayTek Vigor3900
Event History
Jun 24, 2020
CVE Published
via MITRE·04:51 PM
Data Sourced
via MITRE·04:51 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this Draytek vulnerability?
The vulnerability ID for this Draytek vulnerability is CVE-2020-14472.
2
What is the severity of CVE-2020-14472?
The severity of CVE-2020-14472 is critical with a severity value of 9.8.
3
Which Draytek devices are affected by CVE-2020-14472?
Draytek Vigor3900, Vigor2960, and Vigor 300B devices before version 1.5.1.1 are affected by CVE-2020-14472.
4
What is the main file affected by the command-injection vulnerabilities?
The mainfunction.cgi file is affected by the command-injection vulnerabilities.
5
How can I fix CVE-2020-14472 on my Draytek device?
To fix CVE-2020-14472, upgrade your Draytek Vigor3900, Vigor2960, or Vigor 300B device to version 1.5.1.1 or higher.