EXPOSURES › CVE-2020-15415
CVE-2020-15415
HIGH ⌖ ON CISA KEV · EXPLOITEDDrayTek routers allow remote code execution via filename injection in Python script uploads.
Vigor3900, Vigor2960, and Vigor300B routers contain a critical OS command injection vulnerability in the cgi-bin/mainfunction.cgi/cvmcfgupload handler that enables remote code execution through shell metacharacters in filenames when text/x-python-script content type is used. This flaw is actively exploited in the wild and poses a severe risk to DIB organizations relying on these devices for network security, as it bypasses standard input validation and allows attackers to execute arbitrary commands on the device OS.
Shame score — A critical RCE vulnerability in widely deployed router hardware that is actively exploited in the wild, indicating a failure in vendor security hygiene and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.