Skip to content

Known CVE

DrayTek Vigor - Command Injection

DrayTek Vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. The vulnerability allows remote attackers to execute arbitrary commands through specially crafted requests to the /cgi-bin/mainfunction.cgi/cvmcfgupload endpoint.

CVE-2020-15415

Critical2020CVSS 9.8CWE-78

cve2020 · draytek · rce · router · kev · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website