PoC Index

CVE-2020-14993

CRITICAL 9.8EPSS 5.3%

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
5.33% chance of exploitation in the next 30 days, 92th percentile
Published
2020-06-23
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related