Skip to content
COOEY

EXPOSURES › CVE-2020-8515

CVE-2020-8515

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8515 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 rceexploited-in-wildsupply-chainnegligence

DrayTek Vigor routers suffered a remote code execution flaw actively exploited in the wild, enabling attackers to take full control of network devices.

The unspecified vulnerability in DrayTek Vigor3900, Vigor2960, and Vigor300B routers allowed remote code execution, meaning attackers could execute arbitrary commands on the devices. For DIB organizations, this represents a severe supply-chain and infrastructure risk, as compromised routers can serve as pivot points for lateral movement or data exfiltration. Organizations must ensure all network hardware is patched and monitored for signs of compromise, especially given the vulnerability's presence in the CISA KEV catalog.

Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a severe, avoidable failure in DrayTek's security posture and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -1.00
cooey ↗ severe-fallout -1.00
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.