LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8515: Multiple DrayTek Vigor Routers Web Management Page Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8515 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

DrayTek Vigor3900, Vigor2960, and Vigor300B routers contain an unspecified vulnerability that allows for remote code execution.

CVE-2020-8515 is a vulnerability in the web management page of certain DrayTek Vigor routers that can allow an attacker to achieve remote code execution. CISA notes that DrayTek Vigor3900, Vigor2960, and Vigor300B routers are affected by an unspecified flaw of this type. For network teams, this matters because management interfaces on edge routers are high-value targets: successful abuse can give an attacker control of the device and a foothold into the networks behind it.

Public detail beyond the CWE and the remote-code-execution outcome is limited. Confirm exact model coverage, fixed firmware, and any prerequisites against the vendor advisory before acting.

How it works

The weakness is classified as CWE-78 (OS command injection). In this class of flaw, input that reaches a web management function is not adequately validated or sanitized before it is passed to an operating-system command interpreter. An attacker who can reach the vulnerable management page may be able to supply crafted input that causes the device to execute attacker-controlled commands with the privileges of the web service or the underlying system.

Because the CISA summary describes the outcome as remote code execution and does not publish further exploit mechanics, defenders should treat any unauthenticated or weakly authenticated exposure of the management interface as potentially sufficient for abuse. Specific request formats, parameters, or preconditions must be confirmed against the vendor advisory; do not rely on unverified public proof-of-concept details.

Am I affected? How to find it in your systems

These devices are typically deployed as edge or branch routers providing WAN connectivity, VPN termination, or small-office routing. Inventory every DrayTek Vigor appliance in your environment, with particular attention to the models named by CISA: Vigor3900, Vigor2960, and Vigor300B. Other Vigor models may also be in scope under the broader “Multiple DrayTek Vigor Routers” description; verify the full list in the vendor advisory.

How to remediate

Patch first. Apply the firmware updates published by DrayTek for the affected models, following the vendor’s installation instructions exactly. CISA’s required action is to apply updates per vendor instructions; confirm the precise fixed versions and any intermediate upgrade steps in the official advisory.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls appropriate to command-injection flaws on network devices.

These measures lower risk but do not eliminate it; treat them as temporary until the official firmware is installed.

If your data may have been exposed

Actively exploited remote-code-execution vulnerabilities on edge devices can lead to full device compromise and subsequent lateral movement or data theft. Known ransomware use is not documented for this CVE. If you suspect exploitation, isolate the affected router, preserve logs and configuration for incident response, rotate any credentials or keys that resided on or passed through the device, and review connected systems for follow-on activity. You can also run a free exposure scan of your email addresses to check whether they appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedDrayTek · Multiple Vigor Routers
WeaknessCWE-78
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities