Vulnerabilities > Draytek > Vigor300B Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-03-26 | CVE-2020-10824 | Out-of-bounds Write vulnerability in Draytek products A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3). | 9.8 |
2020-03-26 | CVE-2020-10823 | Out-of-bounds Write vulnerability in Draytek products A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 1 of 3). | 9.8 |
2020-02-01 | CVE-2020-8515 | OS Command Injection vulnerability in Draytek products DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. | 9.8 |