Описание
DrayTek Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1 is affected by a remote code injection/execution vulnerability.
DrayTek Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1 is affected by a remote code injection/execution vulnerability.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-14472
- https://gist.github.com/Cossack9989/fa9718434ceee4e6d4f6b0ad672c10f1
- https://gist.github.com/WinMin/46165779215f1d47ec257210428c0240
- https://github.com/Cossack9989/Vulns/blob/master/IoT/CVE-2020-14472.md
- https://www.draytek.com/about/security-advisory/vigor3900-/-vigor2960-/-vigor300b-remote-code-injection/execution-vulnerability-(cve-2020-14472)
Связанные уязвимости
CVSS3: 9.8
nvd
больше 5 лет назад
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.
CVSS3: 9.8
fstec
больше 5 лет назад
Уязвимость сценария mainfunction.cgii веб-интерфейса микропрограммного обеспечения маршрутизаторов DrayTek Vigor, позволяющая нарушителю внедрить произвольную команду