CVE-2020-14993
Published · Updated
25Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Attendepss 5.5%
from disclosure to weapon
Published on NVDJun 23
VulnCheck+1886d
exploitation probability
5.5%top 7% of all CVEs
observed exploitation
yesVulnCheck
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Affected products
n/a · n/a