CVE-2020-14993observed exploitation

CVE-2020-14993

Published · Updated

25Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Attendepss 5.5%
from disclosure to weapon
Published on NVDJun 23
VulnCheck+1886d
exploitation probability
5.5%top 7% of all CVEs
observed exploitation
yesVulnCheck
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Affected products
n/a · n/a