References https://blog.csdn.net/weixin_42181573/article/details/135839915 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/iot/DrayTek%E4%BC%81%E4%B8%9A%E7%BD%91%E7%BB%9C%E8%AE%BE%E5%A4%87-%E8%BF%9C%E7%A8%8B%E5%91%BD%E4%BB%A4%E6%89%A7%E8%A1%8C-CVE-2020-8515.md https://blog.netlab.360.com/two-zero-days-are-targeting-draytek-broadband-cpe-devices/ https://zhuanlan.zhihu.com/p/714732337 https://www.ithome.com.tw/news/166783 https://avd.aliyun.com/detail?id=AVD-2024-43027 https://www.cnvd.org.cn/flaw/show/CNVD-2022-31821 https://www.sxxdckj.com/cms/a/DrayTek-Vigor-yuan-cheng-ming-ling-zhu-ru-lou-dong.html https://stack.chaitin.com/vuldb/detail/17fe452c-91f7-4ea2-bdff-dabac02a59af https://jiwo.org/ken/detail.php?id=2735 https://www.ctfiot.com/77977.html https://www.armis.com/threat-alert/draytek-vigor-os-command-injection-vulnerability/ https://nvd.nist.gov/vuln/detail/cve-2024-12987 https://www.tenable.com/plugins/pipeline/issues/194453 https://stack.chaitin.com/vuldb/detail/4a3e590f-1de9-4bcc-8c53-657a504fc77f https://www.sentinelone.com/vulnerability-database/cve-2022-50994/ https://www.nsfocus.net/vulndb/104387 https://www.draytek.com/about/security-advisory/ https://censys.com/advisory/cve-2024-41592/
Related VulnerabilitiesPoCCVE-2020-15415: DrayTek Vigor - Command InjectionPoCCVE-2020-8515: DrayTek - Remote Code ExecutionPoCCVE-2021-20123: Draytek VigorConnect 1.6.0-B - Local File InclusionPoCCVE-2021-20124: Draytek VigorConnect 6.0-B3 - Local File InclusionPoCCVE-2024-12987: DrayTek Vigor - Command InjectionPoCCVE-2020-8515: DrayTek pre-auth RCEDrayTek Vigor2960 Router 命令注入漏洞DrayTek Vigor 路由器缓冲区溢出漏洞 可致远程代码执行DrayTek Vigor AP910C 路由器 /goform/addRouting 远程命令执行漏洞PoCdraytek路由器addrouting命令执行漏洞Draytek vigor 2960 CVE-2023-1163 任意文件读取漏洞DrayTek Vigor 2960路由器 CVE-2023-1162 命令注入漏洞DrayTek Vigor AP910C 路由器默认口令漏洞