CyberSec.Space Logo
CVEブラウザに戻る

CVE-2020-15415

Known Exploited (CISA KEV)CRITICAL
9.8
CVSS Severity Score
EPSS Score82.5920%
EPSS Percentile95.33th
Published2020年6月30日
Last Modified2025年11月7日

Vulnerability Description

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

Affected Platforms (CPE)

💻
Draytek

Vigor3900 Firmware

< 1.5.1
💻
Draytek

Vigor2960 Firmware

< 1.5.1
💻
Draytek

Vigor300b Firmware

< 1.5.1

References & Advisories

関連する脆弱性情報