← Vulnerability feed

Vulnerability record · CVE-2020-15415 · published 30 June 2020

CVE-2020-15415: DrayTek Vigor routers OS command injection in cvmcfgupload

Draytek · Vigor3900 Firmware

DrayTek Vigor3900, Vigor2960 and Vigor300B devices before firmware 1.5.1 allow OS command injection through shell metacharacters in a filename uploaded to cgi-bin/mainfunction.cgi/cvmcfgupload when the text/x-python-script content type is used. The flaw is distinct from CVE-2020-14472 and is rated critical by NVD. It matters because the affected devices are internet-facing edge routers, so successful exploitation gives an attacker a foothold on the network perimeter.

9.8 CVSS 3.1 Critical CISA KEV since 30 Sep 2024 EPSS 84% · top 0.3% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
84%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
3Affected product versions listed by NVD
5References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityThe flaw is an unauthenticated network-reachable OS command injection on edge routers, is in CISA KEV, and has a very high EPSS score.

What it is

DrayTek Vigor3900, Vigor2960 and Vigor300B devices before firmware 1.5.1 allow OS command injection through shell metacharacters in a filename uploaded to cgi-bin/mainfunction.cgi/cvmcfgupload when the text/x-python-script content type is used. The flaw is distinct from CVE-2020-14472 and is rated critical by NVD. It matters because the affected devices are internet-facing edge routers, so successful exploitation gives an attacker a foothold on the network perimeter.

Impact

An unauthenticated remote attacker can execute arbitrary shell commands on the device, leading to full compromise of confidentiality, integrity and availability. That typically means control of the router and a position to pivot into the internal network.

Attack surface

The vulnerability is reachable over the network through the cgi-bin/mainfunction.cgi/cvmcfgupload endpoint; the CVSS vector indicates no privileges and no user interaction are required. Any exposed management interface on an unpatched device is a candidate target.

Exploitation

CVE-2020-15415 is listed in CISA KEV with a due date of 2024-10-21, and EPSS gives a 30-day probability of 0.8448 (99.7th percentile), indicating active exploitation is expected. Public exploit code is referenced, and CISA records no known ransomware campaign use.

What to do

  • Upgrade Vigor3900, Vigor2960 and Vigor300B devices to firmware 1.5.1 or later as the primary fix.
  • If patching is not immediately possible, follow the vendor security advisory mitigations or discontinue use of the affected device per CISA guidance.
  • Remove management interfaces from direct internet exposure and restrict access to trusted administrative networks.
  • Monitor vendor advisories for updated firmware and re-check devices that cannot be upgraded.
  • Inventory all affected Vigor models to confirm which units remain unpatched.

Detection

  • Review web server and device logs for requests to cgi-bin/mainfunction.cgi/cvmcfgupload, especially with text/x-python-script content types or unusual filenames containing shell metacharacters.
  • Alert on unexpected outbound connections or command execution artifacts originating from Vigor router management addresses.
  • Hunt for filenames in upload requests containing characters such as semicolons, pipes, backticks or command substitution syntax.
  • Correlate device firmware versions against the 1.5.1 fixed release to identify unpatched units.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-15415 to the Known Exploited Vulnerabilities catalog on 30 September 2024 as "DrayTek Multiple Vigor Routers OS Command Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 21 October 2024.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15415 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-8515DrayTek Vigor routers unauthenticated OS command injection in web managementDrayTek Vigor2960, Vigor3900 and Vigor300B firmware pass shell metacharacters to cgi-bin/mainfunction.cgi, allowing OS command injection. Because the…KEVEPSS 100%analysed6.9CVE-2024-12987DrayTek Vigor router web interface OS command injectionDrayTek Vigor2960 and Vigor300B firmware 1.5.1.4 contain an OS command injection flaw in the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint of the w…KEVEPSS 98%analysed9.8CVE-2024-51252Draytek vigor3900 firmware os command injection vulnerabilityIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun…EPSS 0.82%9.8CVE-2024-51255Draytek vigor3900 firmware command injection vulnerabilityDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_…EPSS 0.39%9.8CVE-2024-51260Draytek vigor3900 firmware command injection vulnerabilityDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_proc…EPSS 0.62%9.8CVE-2024-51259Draytek vigor3900 firmware command injection vulnerabilityDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cac…EPSS 0.35%9.8CVE-2024-51298Draytek vigor3900 firmware code injection vulnerabilityIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel…EPSS 0.62%9.8CVE-2024-48153Draytek vigor3900 firmware command injection vulnerabilityDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subco…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2020-15415), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.