CVE detail
CVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 17.5 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
26 source links · newest first
DrayTek has shared some clarifications regarding the recent attacks causing router reboots, but some questions remain unanswered.
newswww.securityweek.comApr 2, 2025, 10:30 AMDrayTek routers around the world are rebooting and the vendor’s statement suggests that it may involve the exploitation of a vulnerability.
newswww.securityweek.comMar 25, 2025, 3:21 PM- Amid Reports of Worldwide Reboots, GreyNoise Observes In-the-Wild Activity Against DrayTek RoutersGreyNoise
GreyNoise is bringing awareness to in-the-wild activity against several known vulnerabilities (CVE-2020-8515, CVE-2021-20123, and CVE-2021-20124) in DrayTek devices.
vendorwww.greynoise.ioMar 25, 2025, 12:00 AM - 20th February – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 20th February, please download our Threat_Intelligence Bulletin TOP ATTACKS AND BREACHES Check Point Research identified a campaign against entities in Armenia, using a new version of OxtaRAT – an AutoIt-based backdoor for remote access and desktop surveillance. The threat actors have been targeting human […]
vendorresearch.checkpoint.comFeb 20, 2023, 4:33 PM A new variant of Mirai — the botnet malware used to launch massive DDoS attacks —has been targeting 13 vulnerabilities in IoT devices connected to Linux servers, according to researchers at Palo Alto Networks’ Unit 42 cybersecurity team. Once the vulnerable devices are compromised by the variant, dubbed V3G4, they can fully controlled by attackers […]
newswww.csoonline.comFeb 17, 2023, 6:04 PM- Mirai V3G4 botnet exploits 13 flaws to target IoT devicesSecurity Affairs
During the second half of 2022, a variant of the Mirai bot, tracked as V3G4, targeted IoT devices by exploiting tens of flaws. Palo Alto Networks Unit 42 researchers reported that a Mirai variant called V3G4 was attempting to exploit several flaws to infect IoT devices from July to December 2022. Below is the list […]
newssecurityaffairs.comFeb 16, 2023, 9:32 PM A recent variant of the Mirai malware has been observed targeting 13 IoT vulnerabilities to ensnare devices into a botnet.
newswww.securityweek.comFeb 16, 2023, 1:56 PMWe observed Mirai variant V3G4 targeting IoT devices in three separate campaigns in 2022.
vendorunit42.paloaltonetworks.comFeb 15, 2023, 2:00 PMSeveral US government agencies have issued a joint cybersecurity advisory to provide information on the techniques and tactics that China-linked threat actors have been using to compromise telecom companies and network services providers.
newswww.securityweek.comJun 9, 2022, 1:00 PMChina-linked threat actors have breached telecommunications companies and network service providers to spy on the traffic and steal data. US NSA, CISA, and the FBI published a joint cybersecurity advisory to warn that China-linked threat actors have breached telecommunications companies and network service providers. The nation-state actors exploit publicly known vulnerabilities to compromise the target […]
newssecurityaffairs.comJun 8, 2022, 9:53 AM- 15th November – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 15th November, please download our Threat Intelligence Bulletin. Top Attacks and Breaches Check Point Research notes a 178% increase in the number of malicious shopping websites, compared to the rest of the year, spotting over 5300 different malicious websites per week ahead of the […]
vendorresearch.checkpoint.comNov 15, 2021, 2:13 PM A newly discovered Golang-based malware is using over 30 exploits in attacks, potentially putting millions of routers and Internet of Things (IoT) at risk of malware infection, according to a warning from AT&T Alien Labs.
newswww.securityweek.comNov 12, 2021, 5:55 PMResearchers at AT&T discovered a new BotenaGo botnet that is using thirty three exploits to target millions of routers and IoT devices. BotenaGo is a new botnet discovered by researchers at AT&T that leverages thirty three exploits to target millions of routers and IoT devices. Below is the list of exploits used by the bot: Vulnerability Affected devices […]
newssecurityaffairs.comNov 12, 2021, 7:16 AMGartner first gave name to the Secure Access Service Edge (SASE) model, effectively defining it. SASE combines WAN and security as a cloud service.
newswww.securityweek.comMay 25, 2021, 1:04 PMOrganizations in the financial and insurance sectors were the most targeted by threat actors in 2020, continuing a trend that was first observed roughly five years ago, IBM Security reports.
newswww.securityweek.comApr 2, 2021, 12:42 PMUnit 42 researchers identify recent network attack trends and analyze vulnerabilities and exploits currently popular with attackers.
vendorunit42.paloaltonetworks.comJan 22, 2021, 2:00 PMThe U.S. National Security Agency this week released an advisory containing information on 25 vulnerabilities that are being actively exploited or targeted by Chinese state-sponsored threat actors.
newswww.securityweek.comOct 21, 2020, 11:06 AM- 25 vulnerabilities exploited by Chinese state-sponsored hackersHelp Net Security
The US Cybersecurity and Infrastructure Security Agency (CISA) has released a list of 25 vulnerabilities Chinese state-sponsored hackers have been recently scanning for or have exploited in attacks. “Most of the vulnerabilities […] can be exploited to gain initial access to victim networks using products that are directly accessible from the Internet and act as gateways to internal networks. The majority of the products are either for remote access or for external web services, and … More →
newswww.helpnetsecurity.comOct 21, 2020, 10:23 AM - NSA details top 25 flaws exploited by China-linked hackersSecurity Affairs
The US National Security Agency (NSA) has shared the list of top 25 vulnerabilities exploited by Chinese state-sponsored hacking groups in attacks in the wild. The US National Security Agency (NSA) has published a report that includes details of the top 25 vulnerabilities that are currently being exploited by China-linked APT groups in attacks in the […]
newssecurityaffairs.comOct 20, 2020, 7:28 PM This includes a brief analysis of two IoT vulnerabilities observed in the wild and the four Mirai variants delivered during the attack.
vendorunit42.paloaltonetworks.comOct 14, 2020, 7:00 PMThe Hoaxcalls IoT botnet expanded the list of targeted devices and has added new distributed denial of service (DDoS) capabilities. DDoS protection services provider Radware warns the Hoaxcalls Internet of Things (IoT) botnet has expanded the list of targeted devices, the experts also noticed that the operators implemented new distributed denial of service (DDoS) capabilities. […]
newssecurityaffairs.comApr 24, 2020, 3:36 PMThe Hoaxcalls Internet of Things (IoT) botnet has expanded the list of targeted devices and has added new distributed denial of service (DDoS) capabilities to its arsenal, DDoS protection services provider Radware reports.
newswww.securityweek.comApr 24, 2020, 8:53 AMThe Hoaxcalls botnet is actively targeting a recently patched SQL injection vulnerability in Grandstream UCM6200 series devices, security researchers warn.
newswww.securityweek.comApr 10, 2020, 10:51 AMA proof-of-concept for CVE-2020-8515 that was made publicly available in March is found being employed by a new DDoS botnet called hoaxcalls.
vendorunit42.paloaltonetworks.comApr 3, 2020, 8:07 PMThreat actors have been exploiting a couple of vulnerabilities affecting some DrayTek enterprise routers in attacks that started before patches were released by the vendor. DrayTek is a Taiwan-based manufacturer of networking equipment, including routers, firewalls, broadband customer premises equipment (CPE), and VPN devices.
newswww.securityweek.comMar 30, 2020, 11:44 AMExperts from Qihoo 360’s NetLab recently spotted two zero-day campaigns targeting DrayTek enterprise-grade networking devices. Since December 2019, researchers from Qihoo 360 observed two different attack groups that are employing two zero-days exploits to take over DrayTek enterprise routers to eavesdrop on FTP and email traffic inside corporate networks. While Netlab360 has found about ~100,000 devices […]
newssecurityaffairs.comMar 28, 2020, 11:27 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2020-15415CVSS 9.8 · Critical
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename w…
- CVE-2024-43027CVSS 8.0 · High
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnera…
- CVE-2021-43118CVSS 9.8 · Critical
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing mal…
- CVE-2021-42911CVSS 9.8 · Critical
A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfunction.cgi file via a crafted…
- CVE-2020-14473CVSS 9.8 · Critical
Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.
- CVE-2020-14472CVSS 9.8 · Critical
On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.