CVE-2023-31447: Code Injection
userlogin.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-31447?
CVE-2023-31447 is a vulnerability found in Draytek Vigor2620 devices before version 3.9.8.4 (and all versions of Vigor2925 devices) that allows attackers to execute arbitrary code.
How does CVE-2023-31447 affect Draytek Vigor2620 devices?
CVE-2023-31447 allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code on Draytek Vigor2620 devices.
What is the severity of CVE-2023-31447?
CVE-2023-31447 has a severity rating of 9.8 (Critical).
How can I fix CVE-2023-31447 on my Draytek Vigor2620 device?
To fix CVE-2023-31447, you should update your Draytek Vigor2620 device firmware to version 3.9.8.4 or later.
Where can I find more information about CVE-2023-31447?
You can find more information about CVE-2023-31447 on the official Draytek website and on the provided GitHub gist.