CVE-2023-6265: DrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal
UNSUPPORTED WHEN ASSIGNED Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this DrayTek vulnerability?
The vulnerability ID for this DrayTek vulnerability is CVE-2023-6265.
What is the title of this DrayTek vulnerability?
The title of this DrayTek vulnerability is DrayTek Vigor2960 mainfunction.cgi dumpSyslog option directory traversal.
What is the severity rating of CVE-2023-6265?
The severity rating of CVE-2023-6265 is 8.1 (High).
How does the vulnerability in DrayTek Vigor2960 occur?
The vulnerability in DrayTek Vigor2960 occurs due to a directory traversal vulnerability in the mainfunction.cgi dumpSyslog 'option' parameter.
How can an attacker exploit this vulnerability?
An authenticated attacker with access to the web management interface can exploit this vulnerability to delete arbitrary files.