// For flags

CVE-2023-6265

DrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal

Severity Score

8.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.

Draytek Vigor2960 v1.5.1.4 y v1.5.1.5 son vulnerables a directory traversal a través del parámetro 'option' mainfunction.cgi dumpSyslog que permite a un atacante autenticado con acceso a la interfaz de administración web eliminar archivos arbitrarios. Vigor2960 ya no es compatible.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-11-22 CVE Reserved
  • 2023-11-22 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-08-02 First Exploit
  • 2024-10-22 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Draytek
Search vendor "Draytek"
Vigor2960 Firmware
Search vendor "Draytek" for product "Vigor2960 Firmware"
1.5.1.4
Search vendor "Draytek" for product "Vigor2960 Firmware" and version "1.5.1.4"
-
Affected
in Draytek
Search vendor "Draytek"
Vigor2960
Search vendor "Draytek" for product "Vigor2960"
--
Safe
Draytek
Search vendor "Draytek"
Vigor2960 Firmware
Search vendor "Draytek" for product "Vigor2960 Firmware"
1.5.1.5
Search vendor "Draytek" for product "Vigor2960 Firmware" and version "1.5.1.5"
-
Affected
in Draytek
Search vendor "Draytek"
Vigor2960
Search vendor "Draytek" for product "Vigor2960"
--
Safe
* End Of Life in some or all products. Do not expect updates.