CyberSec.Space Logo
Back to CVE Browser

CVE-2020-15415

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score82.5920%
EPSS Percentile95.33th
PublishedJun 30, 2020
Last ModifiedNov 7, 2025

Vulnerability Description

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

Affected Platforms (CPE)

πŸ’»
Draytek

Vigor3900 Firmware

< 1.5.1
πŸ’»
Draytek

Vigor2960 Firmware

< 1.5.1
πŸ’»
Draytek

Vigor300b Firmware

< 1.5.1

References & Advisories

Related Vulnerabilities