CVE-2020-8515(draytek / vigor2960)

LOWCVSS 9.8 · CRITICALCISA KEV

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

0.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • vigor2960
  • vigor2960_firmware
  • vigor300b
  • vigor300b_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
vigor2960vigor2960_firmwarevigor300bvigor300b_firmwarevigor3900vigor3900_firmware

5 versions affected across 6 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Referenced assets1 URL
By indicator
Full discourse1 post
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: High CVE: CVE-2020-8515 Product: DrayTek / Vigor Routers Summary: VulnCheck reports real-world exploitation activity affecting DrayTek / Vigor Routers. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 03 Apr 2020 Source: https://vulncheck.com/xdb/7f8fd0ec1666 #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #DrayTek #VigorRouters #CVE_2020_8515 #ActiveExploitation #Exploit

    0000031
    224 followersView on X
CPE platform detail8 entries

8 of 8 entries

PartVendorProductVersionTarget SWTarget HW
HWdraytekvigor2960---
OSdraytekvigor2960_firmware1.3.1--
HWdraytekvigor300b---
OSdraytekvigor300b_firmware1.3.3--
OSdraytekvigor300b_firmware1.4.2.1--
OSdraytekvigor300b_firmware1.4.4--
HWdraytekvigor3900---
OSdraytekvigor3900_firmware1.4.4--

Explore more