S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2020-8515 Scanner

CVE-2020-8515 scanner - Remote Code Execution (RCE) vulnerability in DrayTek Vigor2960, Vigor3900, Vigor300B

Est. Time~30 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2020-8515
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The DrayTek Vigor2960, Vigor3900, and Vigor300B devices are multi-WAN routers suitable for small and medium businesses that require reliable and secure VPN connectivity. These routers feature high-performance hardware, advanced security protocols, and a user-friendly web interface that allows network administrators to configure complex network setups with just a few clicks. The DrayTek routers are used by companies for critical applications such as remote working, video conferencing, and cloud computing.

The CVE-2020-8515 vulnerability detected in DrayTek routers allows remote code execution as a root user without the need for authentication. This vulnerability can be exploited through shell metacharacters to the cgi-bin/mainfunction.cgi URI. Hackers can send a malicious payload to the router, which the device automatically processes and executes. This vulnerability may lead to severe damage to the victim's network, including data loss, data theft, and network shutdown.

When exploited, CVE-2020-8515 vulnerability can enable attackers to gain root privileges, bypass security checks, and execute arbitrary code on the affected DrayTek routers. This means attackers can take complete control of both the router and the network that the router serves, leading to all network traffic being intercepted and exposed. Breaching the security of the network can result in a loss of sensitive information, ultimately exposing the company to financial and reputational damage.

Thanks to the pro features of the s4e.io platform, businesses can easily and quickly learn about vulnerabilities in their digital assets. By subscribing to the platform, network administrators can receive real-time alerts about vulnerability threats and take immediate action to mitigate the risks associated with such vulnerabilities. With an emphasis on proactive security measures, the s4e.io platform helps businesses protect their networks, markets, and reputation, ensuring their continued success in the digital world.

 

REFERENCES

Solution Advice

The following precautions can be taken to protect against this vulnerability:

  • Ensure the router firmware is updated to the latest version (Vigor3900/2960/300B v1.5.1).
  • Block all incoming connections to the router management ports from the internet.
  • Use strong passwords and two-factor authentication on router accounts.
  • Disable the default admin account and create separate accounts with limited permissions.
  • Implement remote access security measures, such as VPN access and geolocation restrictions.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.