CVE-2020-15415criticalunder attackCWE-78

CVE-2020-15415

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 84%
from disclosure to weapon
Published on NVDJun 30
CISA KEV+1553d
exploitation probability
84%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2024-10-21

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

A vulnerability in DrayTek routers allows attackers to run arbitrary commands on the device by uploading a file with a specially crafted filename containing shell commands. This bypasses security controls and gives attackers complete control over the router.

Technical detail

CWE-78 OS Command Injection in cgi-bin/mainfunction.cgi/cvmcfgupload endpoint allows unauthenticated remote command execution when text/x-python-script content type is used with shell metacharacters in the filename parameter. No authentication required; successful exploitation results in arbitrary code execution with device privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a