CVE-2020-14993

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:draytek:vigor300b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor300b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:draytek:vigor2960_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:draytek:vigor3900_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor3900:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-06-23 12:15

Updated : 2024-02-04 21:00


NVD link : CVE-2020-14993

Mitre link : CVE-2020-14993

CVE.ORG link : CVE-2020-14993


JSON object : View

Products Affected

draytek

  • vigor300b_firmware
  • vigor2960
  • vigor300b
  • vigor2960_firmware
  • vigor3900_firmware
  • vigor3900
CWE
CWE-787

Out-of-bounds Write