DrayTek Vigor devices contain a command injection vulnerability in the cvmcfgupload functionality. The vulnerability allows remote attackers to execute arbitrary commands through specially crafted requests to the /cgi-bin/mainfunction.cgi/cvmcfgupload endpoint.
id: CVE-2020-15415
info:
name: DrayTek Vigor - Command Injection
author: ritikchaddha
severit
...