CVE-2020-19664: DrayTek VIGOR2960 Firmware

High severity, CVSS 8.8. EPSS: 5.5% chance of exploitation in the next 30 days.

DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.

Affected products

  • DrayTek VIGOR2960 Firmware: up to and including 1.5.1

Published 2020-12-31. Last modified 2026-06-17.