Vulnerability record · CVE-2020-15415 · published 30 June 2020
CVE-2020-15415: DrayTek Vigor routers OS command injection in cvmcfgupload
Draytek · Vigor3900 Firmware
DrayTek Vigor3900, Vigor2960 and Vigor300B devices before firmware 1.5.1 allow OS command injection through shell metacharacters in a filename uploaded to cgi-bin/mainfunction.cgi/cvmcfgupload when the text/x-python-script content type is used. The flaw is distinct from CVE-2020-14472 and is rated critical by NVD. It matters because the affected devices are internet-facing edge routers, so successful exploitation gives an attacker a foothold on the network perimeter.
Description
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is an unauthenticated network-reachable OS command injection on edge routers, is in CISA KEV, and has a very high EPSS score.
What it is
DrayTek Vigor3900, Vigor2960 and Vigor300B devices before firmware 1.5.1 allow OS command injection through shell metacharacters in a filename uploaded to cgi-bin/mainfunction.cgi/cvmcfgupload when the text/x-python-script content type is used. The flaw is distinct from CVE-2020-14472 and is rated critical by NVD. It matters because the affected devices are internet-facing edge routers, so successful exploitation gives an attacker a foothold on the network perimeter.
Impact
An unauthenticated remote attacker can execute arbitrary shell commands on the device, leading to full compromise of confidentiality, integrity and availability. That typically means control of the router and a position to pivot into the internal network.
Attack surface
The vulnerability is reachable over the network through the cgi-bin/mainfunction.cgi/cvmcfgupload endpoint; the CVSS vector indicates no privileges and no user interaction are required. Any exposed management interface on an unpatched device is a candidate target.
Exploitation
CVE-2020-15415 is listed in CISA KEV with a due date of 2024-10-21, and EPSS gives a 30-day probability of 0.8448 (99.7th percentile), indicating active exploitation is expected. Public exploit code is referenced, and CISA records no known ransomware campaign use.
What to do
- Upgrade Vigor3900, Vigor2960 and Vigor300B devices to firmware 1.5.1 or later as the primary fix.
- If patching is not immediately possible, follow the vendor security advisory mitigations or discontinue use of the affected device per CISA guidance.
- Remove management interfaces from direct internet exposure and restrict access to trusted administrative networks.
- Monitor vendor advisories for updated firmware and re-check devices that cannot be upgraded.
- Inventory all affected Vigor models to confirm which units remain unpatched.
Detection
- Review web server and device logs for requests to cgi-bin/mainfunction.cgi/cvmcfgupload, especially with text/x-python-script content types or unusual filenames containing shell metacharacters.
- Alert on unexpected outbound connections or command execution artifacts originating from Vigor router management addresses.
- Hunt for filenames in upload requests containing characters such as semicolons, pipes, backticks or command substitution syntax.
- Correlate device firmware versions against the 1.5.1 fixed release to identify unpatched units.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-15415 to the Known Exploited Vulnerabilities catalog on 30 September 2024 as "DrayTek Multiple Vigor Routers OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 October 2024.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/CLP-team/Vigor-Commond-Injection | Exploit |
| https://www.draytek.com/about/security-advisory | Vendor Advisory |
| https://github.com/CLP-team/Vigor-Commond-Injection | Exploit |
| https://www.draytek.com/about/security-advisory | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15415 | US Government Resource |
Track CVE-2020-15415 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-15415), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.