VendorsDrayTekvigor2960_firmware1.5.1.4
Vulnerabilities

DrayTek Vigor2960 Firmware 1.3.1 Beta 1.5.1.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2024-12987
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
Published 2024-12-27 · Analyzed
9.8KEVEPSS 0.981
CVE-2023-6265
DrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal
Published 2023-11-22 · Modified
8.1EPSS 0.018
CVE-2023-24229
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands via the mainfunction.cgi 'parameter' parameter. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Published 2023-03-15 · Modified
7.8EPSS 0.067
CVE-2023-1009
DrayTek Vigor 2960 Web Management Interface mainfunction.cgi sub_1DF14 path traversal
Published 2023-02-24 · Modified
6.5EPSS 0.157