EXPOSURES › CVE-2020-8515
CVE-2020-8515
HIGH ⌖ ON CISA KEV · EXPLOITEDDrayTek Vigor routers suffered a remote code execution flaw actively exploited in the wild, enabling attackers to take full control of network devices.
The unspecified vulnerability in DrayTek Vigor3900, Vigor2960, and Vigor300B routers allowed remote code execution, meaning attackers could execute arbitrary commands on the devices. For DIB organizations, this represents a severe supply-chain and infrastructure risk, as compromised routers can serve as pivot points for lateral movement or data exfiltration. Organizations must ensure all network hardware is patched and monitored for signs of compromise, especially given the vulnerability's presence in the CISA KEV catalog.
Shame score — The vulnerability was actively exploited in the wild and linked to ransomware campaigns, indicating a severe, avoidable failure in DrayTek's security posture and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.