CVE-2020-14993: DrayTek VIGOR2960 Firmware
Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.
A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.
Affected products
- DrayTek VIGOR2960 Firmware: before 1.5.1.1 (fixed in 1.5.1.1)
- DrayTek VIGOR300B Firmware: before 1.5.1.1 (fixed in 1.5.1.1)
- DrayTek VIGOR3900 Firmware: before 1.5.1.1 (fixed in 1.5.1.1)
Published 2020-06-23. Last modified 2026-06-17.