Vulnerabilities (CVE)

Filtered by vendor Draytek Subscribe
Filtered by product Vigor2960
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-6265 1 Draytek 2 Vigor2960, Vigor2960 Firmware 2023-12-19 N/A 8.1 HIGH
** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.
CVE-2023-24229 1 Draytek 2 Vigor2960, Vigor2960 Firmware 2023-11-22 N/A 7.8 HIGH
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2020-19664 1 Draytek 2 Vigor2960, Vigor2960 Firmware 2021-07-21 6.5 MEDIUM 8.8 HIGH
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.