peter bassill · operator
$ cve CVE-2020-14993 JSON

CVE-2020-14993

9.8
CRITICAL · CVSS 3.1 · EPSS 5.5% (pctl 93)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code via the formuserphonenumber parameter in an authusersms action to mainfunction.cgi.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS5.54% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploitnone known
Published2020-06-23
Last modified2026-06-17

Affected (6)

VendorProduct
draytekvigor2960
draytekvigor2960 firmware
draytekvigor300b
draytekvigor300b firmware
draytekvigor3900
draytekvigor3900 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD