CVE-2020-15415: DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.
Other sources
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
DrayTek Vigor3900to a version that resolves this vulnerability.Fixed in 1.5.1 - Upgrade
Upgrade
DrayTek Vigor2960to a version that resolves this vulnerability.Fixed in 1.5.1 - Upgrade
Upgrade
DrayTek Vigor300Bto a version that resolves this vulnerability.Fixed in 1.5.1 - Compensating control
Discontinue use of the product if mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2020-15415?
CVE-2020-15415 is a vulnerability found in DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, allowing remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used.
How severe is CVE-2020-15415?
CVE-2020-15415 has a severity rating of 9.8 (Critical).
Which DrayTek devices are affected by CVE-2020-15415?
DrayTek Vigor3900, Vigor2960, and Vigor300B devices before version 1.5.1 are affected by CVE-2020-15415.
How can CVE-2020-15415 be exploited?
CVE-2020-15415 can be exploited by using shell metacharacters in a filename when the text/x-python-script content type is used on vulnerable DrayTek devices.
Is there a patch or update available for CVE-2020-15415?
Yes, updating DrayTek Vigor3900, Vigor2960, and Vigor300B devices to version 1.5.1 or later will fix the vulnerability.