CVE-2020-10828
- EPSS 13.42%
- Veröffentlicht 26.03.2020 17:15:23
- Zuletzt bearbeitet 05.05.2025 17:15:57
A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.
CVE-2020-10827
- EPSS 13.42%
- Veröffentlicht 26.03.2020 17:15:23
- Zuletzt bearbeitet 05.05.2025 17:15:56
A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request.
- EPSS 29.96%
- Veröffentlicht 26.03.2020 17:15:23
- Zuletzt bearbeitet 05.05.2025 17:15:55
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.
CVE-2020-10825
- EPSS 5.52%
- Veröffentlicht 26.03.2020 17:15:23
- Zuletzt bearbeitet 05.05.2025 17:15:55
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 3 of ...
CVE-2020-10824
- EPSS 5.52%
- Veröffentlicht 26.03.2020 17:15:23
- Zuletzt bearbeitet 05.05.2025 17:15:54
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).
CVE-2020-10823
- EPSS 9.58%
- Veröffentlicht 26.03.2020 17:15:23
- Zuletzt bearbeitet 05.05.2025 17:15:54
A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 1 of 3).
- EPSS 94.36%
- Veröffentlicht 01.02.2020 13:15:12
- Zuletzt bearbeitet 07.11.2025 22:04:15
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue h...