CVE-2020-15415

CVE Published 2020-06-30
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) draytek
Related Product(s) vigor300b_firmware, vigor2960_firmware, vigor3900_firmware
Exploitation Reported (CISA KEV) 2024-09-30
CVSS 3 Base Score 9.8 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References