/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960,...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated May 5, 2025
Description
Published by the National Vulnerability Database
Mar 26, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
May 5, 2025
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mode.
References