CVE-2020-8515 Details
Description
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
A remote code execution vulnerability has been identified in DrayTek Vigor2960, Vigor3900, and Vigor300B routers, allowing unauthenticated users to execute commands as root. The vulnerability arises from the improper handling of shell metacharacters in the web management interface, specifically through the cgi-bin/mainfunction.cgi URI. Affected Vigor300B versions include 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta. This issue has been addressed in the Vigor3900, Vigor2960, and Vigor300B v1.5.1 firmware release.
Users are advised to upgrade to DrayTek Vigor3900, Vigor2960, or Vigor300B version 1.5.1 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 4, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| Multiple DrayTek Vigor Routers Web Management Page Vulnerability | Nov 3, 2021 | May 3, 2022 | Apply updates per vendor instructions. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| draytek vigor2960 firmware | 1.3.1 beta |
CPE
Remediation
| |
| draytek vigor2960 | All versions |
CPE
Remediation
| |
| draytek vigor300b firmware | 1.3.3 beta 1.4.2.1 beta 1.4.4 beta |
CPE
Remediation
| |
| draytek vigor300b | All versions |
CPE
Remediation
| |
| draytek vigor3900 firmware | 1.4.4 beta |
CPE
Remediation
| |
| draytek vigor3900 | All versions |
CPE
Remediation
| |
Change History
17 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 7, 2025 | Modified Analysis | [email protected] |
| Oct 22, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 28, 2025 | Modified Analysis | [email protected] |
| Feb 4, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Jul 25, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Jan 1, 2022 | Modified Analysis | [email protected] |
| Jul 21, 2021 | CWE Remap | [email protected] |
| Mar 31, 2020 | CVE Modified | [email protected] |
| Feb 13, 2020 | Initial Analysis | [email protected] |
| Feb 10, 2020 | CVE Modified | [email protected] |