Overview
- Description
- DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Known exploits
Data from CISA
- Vulnerability name
- Multiple DrayTek Vigor Routers Web Management Page Vulnerability
- Exploit added on
- Nov 3, 2021
- Exploit action due
- May 3, 2022
- Required action
- Apply updates per vendor instructions.
Weaknesses
- nvd@nist.gov
- CWE-78
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:draytek:vigor2960_firmware:1.3.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0446969-43B3-46A1-81A2-EBB22EAA3C01" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "8FDA3905-67DD-4F31-AFCF-014F1D7CCC1F" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:draytek:vigor300b_firmware:1.3.3:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6D18DBBE-382C-4047-8E37-95EC99D321A7" }, { "criteria": "cpe:2.3:o:draytek:vigor300b_firmware:1.4.2.1:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "ABA6F900-F922-45FB-B7B5-DC558BE1A8ED" }, { "criteria": "cpe:2.3:o:draytek:vigor300b_firmware:1.4.4:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "45DDB337-B522-4ED4-9266-C73882C1A30B" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:draytek:vigor300b:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DA5B988D-ED1A-4CBF-8B34-C5B03A55ED52" } ], "operator": "OR" } ], "operator": "AND" }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:o:draytek:vigor3900_firmware:1.4.4:beta:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "42BB787F-2B02-4AAB-B381-5184B5629B70" } ], "operator": "OR" }, { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:draytek:vigor3900:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "FEECFBBC-5551-4135-9194-4216A39B04B9" } ], "operator": "OR" } ], "operator": "AND" } ]