CVE-2020-19664: OS Command Injection
Published Dec 31, 2020
·Updated
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
Affected Software
2 affected components
DrayTek Vigor2960 Firmware<=1.5.1
DrayTek Vigor2960
Event History
Dec 31, 2020
CVE Published
via MITRE·01:23 AM
Data Sourced
via MITRE·01:23 AM
Description
Frequently Asked Questions
1
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2020-19664.
2
What is the severity of CVE-2020-19664?
The severity of CVE-2020-19664 is high with a CVSS score of 8.8.
3
How does CVE-2020-19664 allow remote command execution?
CVE-2020-19664 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
4
Which software versions are affected by CVE-2020-19664?
DrayTek Vigor2960 1.5.1 firmware version is affected.
5
How can I fix CVE-2020-19664?
To fix CVE-2020-19664, update your DrayTek Vigor2960 firmware to a version that has patched the vulnerability.