First published: Mon Aug 21 2023(Updated: )
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Draytek Vigor2620 Firmware | <3.9.8.4 | |
Draytek Vigor2620 | ||
Draytek Vigor2625 Firmware | ||
Draytek Vigor2625 | ||
All of | ||
Draytek Vigor2620 | ||
Draytek Vigor2620 Firmware | <3.9.8.4 | |
All of | ||
Draytek Vigor2625 | ||
Draytek Vigor2625 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-31447 is a vulnerability found in Draytek Vigor2620 devices before version 3.9.8.4 (and all versions of Vigor2925 devices) that allows attackers to execute arbitrary code.
CVE-2023-31447 allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code on Draytek Vigor2620 devices.
CVE-2023-31447 has a severity rating of 9.8 (Critical).
To fix CVE-2023-31447, you should update your Draytek Vigor2620 device firmware to version 3.9.8.4 or later.
You can find more information about CVE-2023-31447 on the official Draytek website and on the provided GitHub gist.