CVE-2020-19664

HIGH WAF: High
CVSS 8.8 Published: 2020-12-31
CWE-78

DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
draytekvigor2960_firmwareup to 1.5.1

References

Back to CVE Database