CVE-2026-3040 Details
Description
A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor confirms that "300B is EoL, and this is an authenticated vulnerability. We don't plan to fix it." This vulnerability only affects products that are no longer supported by the maintainer.
A command injection vulnerability has been identified in the DrayTek Vigor 300B router, affecting versions through 1.5.1.6. The issue arises in the Web Management Interface, specifically within the 'uploadlangs' function of 'mainfunction.cgi'. The vulnerability allows for OS command injection by manipulating the 'File' argument during language package uploads. This flaw can be exploited remotely and requires authentication. The vendor has acknowledged that the Vigor 300B is no longer supported and does not plan to issue a fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/master-abc/cve/issues/42 | [email protected] | ExploitIssue Tracking |
| https://vuldb.com/?ctiid.347394 | [email protected] | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.347394 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.757126 | [email protected] | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| draytek vigor300b firmware | <= 1.5.1.6 |
CPE
Remediation
| |
| draytek vigor300b | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 26, 2026 | Initial Analysis | [email protected] |
| Feb 23, 2026 | New CVE Received | [email protected] |