ZeroHour

CVE-2020-15415

KEV PoC large

Unauthenticated OS Command Injection in DrayTek Vigor3900/2960/300B Routers

CISA: DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

CVSS 3.1
9.8 critical
EPSS
84%p100
Published
()
KEV added
AI analysis

DrayTek Vigor3900, Vigor2960, and Vigor300B routers running firmware before 1.5.1 contain an unauthenticated OS command injection flaw (CWE-78) in the cvmcfgupload handler of the web management interface (cgi-bin/mainfunction.cgi/cvmcfgupload), distinct from CVE-2020-14472. A remote attacker sends an upload request using the text/x-python-script content type with shell metacharacters embedded in the filename, which the device passes to a shell without sanitization, achieving arbitrary command execution. Because no credentials or user interaction are required, an internet-exposed management interface can be fully compromised, giving the attacker control of the router and a foothold into the network behind it. Any organization or site running one of these three Vigor models on pre-1.5.1 firmware is affected, especially where the web UI is reachable from the internet. Exploitation is confirmed: a public proof-of-concept exists, EPSS rates 30-day exploitation probability at 84.5% (100th percentile), CISA added the bug to the Known Exploited Vulnerabilities catalog on 2024-09-30, and recent reporting ties Mirai V3G4 botnet activity to campaigns exploiting a batch of 13 IoT flaws.

What to do: Upgrade Vigor3900, Vigor2960, and Vigor300B firmware to version 1.5.1 or later per DrayTek's instructions, consistent with the CISA KEV required action (apply vendor mitigations or discontinue use). Until patched, do not expose the web management interface to the internet (restrict to trusted management IPs or VPN access) and hunt for compromise indicators such as unexpected processes, altered configurations, or Mirai-like scanning traffic. Check access logs for requests to /cgi-bin/mainfunction.cgi/cvmcfgupload using the text/x-python-script content type with metacharacters in the filename.

Affected
DrayTek Vigor3900firmware before 1.5.1
DrayTek Vigor2960firmware before 1.5.1
DrayTek Vigor300Bfirmware before 1.5.1
Estimated exposure
large≈100,000 internet-exposed Vigor3900/2960/300B devices (order-of-magnitude estimate) — DrayTek business routers are widely deployed and hundreds of thousands of DrayTek devices appear in public internet scans; this popular business-class line plausibly accounts for on the order of 100,000 exposed devices, though this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

CISA Known Exploited Vulnerability
Affected
DrayTek Multiple Vigor Routers
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
draytek
Products
vigor3900 firmware, vigor2960 firmware, vigor300b firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Mirai Variant V3G4 Targets IoT Devices

Unit 42 tracked the Mirai variant V3G4 exploiting 13 vulnerabilities across IoT devices and servers from July-December 2022 to build a DDoS botnet.

From July to December 2022, Unit 42 observed three campaigns spreading V3G4, a Mirai botnet variant, by exploiting 13 vulnerabilities, including CVE-2022-26134 in Atlassian Confluence and CVE-2019-15107 in Webmin. The campaigns shared the same C2 domains containing the string 8xl9, nearly identical shell script downloaders, and the same XOR keys, suggesting a single threat actor. The malware brute-forces telnet and SSH credentials, terminates rival botnet processes via a stop list, and receives DDoS commands from its C2. Compromised servers and networking devices are absorbed into the botnet for further attacks.

Palo Alto Unit 42 · 29d agoMalware in the wildCVE-2012-4869CVE-2014-9727CVE-2017-5173+6 CVEs