DrayTek records
134 published records for vendor draytek.
Researcher profile
- Entered KEV
- 5 · 3.7%
- Weaponized
- 5 · 3.7%
- Pre-auth RCE
- 22
- With a fix record
- 1.5%
- Median publish → KEV
- 1056 days
Recurring classes
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')40
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')28
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')21
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-787 Out-of-bounds Write8
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')7
The weakness classes this vendor ships most often: where to look.
CWEAll records
134 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2020-8515Weaponized | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executidraytek · vigor2960 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Feb 1, 2020 |
94Now | CVE-2020-15415Weaponized | On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution vdraytek · vigor3900 firmware · CWE-78 | Critical9.8 | KEV | 84.5% | Jun 30, 2020 |
89Now | CVE-2021-20124Weaponized | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint.draytek · vigorconnect · CWE-22 | High7.5 | KEV | 96.3% | Oct 13, 2021 |
87Now | CVE-2021-20123Weaponized | A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet edraytek · vigorconnect · CWE-22 | High7.5 | KEV | 90.2% | Oct 13, 2021 |
86Now | CVE-2024-12987Weaponized | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injectiondraytek · vigor300b firmware · CWE-77 | Medium6.9 | KEV | 98.1% | Dec 27, 2024 |
51Plan | CVE-2020-10826No exploit | /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injectidraytek · vigor300b firmware · CWE-77 | Critical9.8 | — | 39.4% | Mar 26, 2020 |
49Plan | CVE-2021-43118No exploit | A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 vidraytek · vigor2960 firmware · CWE-77 | Critical9.8 | — | 34.8% | Mar 29, 2022 |
49Plan | CVE-2022-32548Proof of concept | An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1.draytek · vigor3910 firmware · CWE-120 | Critical9.8 | — | 34.0% | Aug 29, 2022 |
45Plan | CVE-2020-10828No exploit | A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achievedraytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 20.9% | Mar 26, 2020 |
45Plan | CVE-2020-10827No exploit | A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achievedraytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 20.9% | Mar 26, 2020 |
43Plan | CVE-2023-1162No exploit | DrayTek Vigor 2960 Web Management Interface mainfunction.cgi command injectiondraytek · vigor 2960 firmware · CWE-77 | High8.8 | — | 26.0% | Mar 3, 2023 |
41Plan | CVE-2020-14993No exploit | A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitdraytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 5.3% | Jun 23, 2020 |
40Plan | CVE-2020-10823No exploit | A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1draytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 4.4% | Mar 26, 2020 |
40Plan | CVE-2020-10824No exploit | A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices befordraytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 4.1% | Mar 26, 2020 |
40Plan | CVE-2020-10825No exploit | A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300Bdraytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 4.1% | Mar 26, 2020 |
40Plan | CVE-2021-20125No exploit | An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek Vigdraytek · vigorconnect · CWE-22 | Critical9.8 | — | 3.9% | Oct 13, 2021 |
40Plan | CVE-2021-42911No exploit | A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in tdraytek · vigor2960 firmware · CWE-134 | Critical9.8 | — | 3.5% | Mar 29, 2022 |
40Plan | CVE-2020-14472No exploit | On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunctiondraytek · vigor300b firmware · CWE-77 | Critical9.8 | — | 2.9% | Jun 24, 2020 |
40Plan | CVE-2020-14473No exploit | Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.draytek · vigor300b firmware · CWE-787 | Critical9.8 | — | 2.3% | Jun 24, 2020 |
40Plan | CVE-2023-47254No exploit | An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commandsdraytek · vigor167 firmware · CWE-78 | Critical9.8 | — | 2.2% | Dec 9, 2023 |
39Monitor | CVE-2024-51138No exploit | Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; draytek · vigor3912 firmware · CWE-121 | Critical9.8 | — | 1.1% | Feb 27, 2025 |
39Monitor | CVE-2024-51139No exploit | Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and eadraytek · vigor2620 firmware · CWE-120 | Critical9.8 | — | 1.0% | Feb 27, 2025 |
39Monitor | CVE-2023-31447No exploit | user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted paydraytek · vigor2620 firmware · CWE-94 | Critical9.8 | — | 0.9% | Aug 21, 2023 |
39Monitor | CVE-2024-41593No exploit | DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a bytedraytek · vigor3912 firmware · CWE-787 | Critical9.8 | — | 0.9% | Oct 3, 2024 |
39Monitor | CVE-2024-51252No exploit | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the redraytek · vigor3900 firmware · CWE-78 | Critical9.8 | — | 0.8% | Nov 1, 2024 |
- CVE-2020-851599Now
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi
CriticalCVSS 9.8KEVWeaponizedEPSS 100%draytek · vigor2960 firmwareFeb 1, 2020
- CVE-2020-1541594Now
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution v
CriticalCVSS 9.8KEVWeaponizedEPSS 84%draytek · vigor3900 firmwareJun 30, 2020
- CVE-2021-2012489Now
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint.
HighCVSS 7.5KEVWeaponizedEPSS 96%draytek · vigorconnectOct 13, 2021
- CVE-2021-2012387Now
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet e
HighCVSS 7.5KEVWeaponizedEPSS 90%draytek · vigorconnectOct 13, 2021
- CVE-2024-1298786Now
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
MediumCVSS 6.9KEVWeaponizedEPSS 98%draytek · vigor300b firmwareDec 27, 2024
- CVE-2020-1082651Plan
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injecti
CriticalCVSS 9.8No exploitEPSS 39%draytek · vigor300b firmwareMar 26, 2020
- CVE-2021-4311849Plan
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 vi
CriticalCVSS 9.8No exploitEPSS 35%draytek · vigor2960 firmwareMar 29, 2022
- CVE-2022-3254849Plan
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1.
CriticalCVSS 9.8Proof of conceptEPSS 34%draytek · vigor3910 firmwareAug 29, 2022
- CVE-2020-1082845Plan
A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve
CriticalCVSS 9.8No exploitEPSS 21%draytek · vigor300b firmwareMar 26, 2020
- CVE-2020-1082745Plan
A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve
CriticalCVSS 9.8No exploitEPSS 21%draytek · vigor300b firmwareMar 26, 2020
- CVE-2023-116243Plan
DrayTek Vigor 2960 Web Management Interface mainfunction.cgi command injection
HighCVSS 8.8No exploitEPSS 26%draytek · vigor 2960 firmwareMar 3, 2023
- CVE-2020-1499341Plan
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbit
CriticalCVSS 9.8No exploitEPSS 5%draytek · vigor300b firmwareJun 23, 2020
- CVE-2020-1082340Plan
A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1
CriticalCVSS 9.8No exploitEPSS 4%draytek · vigor300b firmwareMar 26, 2020
- CVE-2020-1082440Plan
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices befor
CriticalCVSS 9.8No exploitEPSS 4%draytek · vigor300b firmwareMar 26, 2020
- CVE-2020-1082540Plan
A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B
CriticalCVSS 9.8No exploitEPSS 4%draytek · vigor300b firmwareMar 26, 2020
- CVE-2021-2012540Plan
An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek Vig
CriticalCVSS 9.8No exploitEPSS 4%draytek · vigorconnectOct 13, 2021
- CVE-2021-4291140Plan
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in t
CriticalCVSS 9.8No exploitEPSS 4%draytek · vigor2960 firmwareMar 29, 2022
- CVE-2020-1447240Plan
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction
CriticalCVSS 9.8No exploitEPSS 3%draytek · vigor300b firmwareJun 24, 2020
- CVE-2020-1447340Plan
Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.
CriticalCVSS 9.8No exploitEPSS 2%draytek · vigor300b firmwareJun 24, 2020
- CVE-2023-4725440Plan
An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands
CriticalCVSS 9.8No exploitEPSS 2%draytek · vigor167 firmwareDec 9, 2023
- CVE-2024-5113839Monitor
Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier;
CriticalCVSS 9.8No exploitEPSS 1%draytek · vigor3912 firmwareFeb 27, 2025
- CVE-2024-5113939Monitor
Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and ea
CriticalCVSS 9.8No exploitEPSS 1%draytek · vigor2620 firmwareFeb 27, 2025
- CVE-2023-3144739Monitor
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted pay
CriticalCVSS 9.8No exploitEPSS 1%draytek · vigor2620 firmwareAug 21, 2023
- CVE-2024-4159339Monitor
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte
CriticalCVSS 9.8No exploitEPSS 1%draytek · vigor3912 firmwareOct 3, 2024
- CVE-2024-5125239Monitor
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the re
CriticalCVSS 9.8No exploitEPSS 1%draytek · vigor3900 firmwareNov 1, 2024