Vulnerabilities > Draytek

DATE CVE VULNERABILITY TITLE RISK
2023-03-15 CVE-2023-24229 Command Injection vulnerability in Draytek Vigor2960 Firmware 1.5.1.4
DrayTek Vigor2960 v1.5.1.4 was discovered to contain a command injection vulnerability via the mainfunction.cgi component.
local
low complexity
draytek CWE-77
7.8
2023-03-03 CVE-2023-23313 Cross-site Scripting vulnerability in Draytek products
Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal.
network
low complexity
draytek CWE-79
6.1
2023-03-03 CVE-2023-1162 Command Injection vulnerability in Draytek Vigor 2960 Firmware 1.5.1.4
A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4.
network
low complexity
draytek CWE-77
8.8
2023-03-03 CVE-2023-1163 Path Traversal vulnerability in Draytek Vigor 2960 Firmware 1.5.1.4
A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4 and classified as problematic.
network
low complexity
draytek CWE-22
6.5
2023-02-24 CVE-2023-1009 Path Traversal vulnerability in Draytek Vigor2960 Firmware 1.5.1.4
A vulnerability classified as problematic has been found in DrayTek Vigor 2960 1.5.1.4.
local
low complexity
draytek CWE-22
5.5
2022-03-29 CVE-2021-42911 Use of Externally-Controlled Format String vulnerability in Draytek products
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted HTTP message containing malformed QUERY STRING, which could let a remote malicious user execute arbitrary code.
network
low complexity
draytek CWE-134
7.5
2022-03-29 CVE-2021-43118 Command Injection vulnerability in Draytek products
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.
network
low complexity
draytek CWE-77
7.5
2021-10-22 CVE-2020-28968 Cross-site Scripting vulnerability in Draytek products
Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module.
network
draytek CWE-79
3.5
2021-10-13 CVE-2021-20123 Path Traversal vulnerability in Draytek Vigorconnect 1.6.0
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint.
network
low complexity
draytek CWE-22
7.8
2021-10-13 CVE-2021-20124 Path Traversal vulnerability in Draytek Vigorconnect 1.6.0
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint.
network
low complexity
draytek CWE-22
7.8