CVE-2020-15415
Published · Updated
Patch now. It under exploitation confirmed by CISA and has a working public exploit.
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
A vulnerability in DrayTek routers allows attackers to run arbitrary commands on the device by uploading a file with a specially crafted filename containing shell commands. This bypasses security controls and gives attackers complete control over the router.
CWE-78 OS Command Injection in cgi-bin/mainfunction.cgi/cvmcfgupload endpoint allows unauthenticated remote command execution when text/x-python-script content type is used with shell metacharacters in the filename parameter. No authentication required; successful exploitation results in arbitrary code execution with device privileges.
The full analysis of this CVE is available in Portuguese →