CVE-2020-8515: Multiple DrayTek Vigor Routers Web Management Page Vulnerability
DrayTek Vigor2960 1.3.1Beta, Vigor3900 1.4.4Beta, and Vigor300B 1.3.3Beta, 1.4.2.1Beta, and 1.4.4Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
Other sources
DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8515?
The severity of CVE-2020-8515 is critical with a score of 9.8.
Which DrayTek Vigor Routers are affected by CVE-2020-8515?
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices are affected.
How can remote code execution be achieved in CVE-2020-8515?
Remote code execution can be achieved as root (without authentication) by using shell metacharacters to the cgi-bin/mainfunction.cgi URI.
Has CVE-2020-8515 been fixed?
Yes, this issue has been fixed in Vigor3900/2960/300B v1.5.1.
What is the Common Weakness Enumeration (CWE) of CVE-2020-8515?
The CWE of CVE-2020-8515 is CWE-78.