CVE-2020-14993
EUVD-2020-712323.06.2020, 12:15
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| draytek | vigor300b_firmware | 𝑥 < 1.5.1.1 |
| draytek | vigor2960_firmware | 𝑥 < 1.5.1.1 |
| draytek | vigor3900_firmware | 𝑥 < 1.5.1.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References