CVE-2023-6265
DrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.
Draytek Vigor2960 v1.5.1.4 y v1.5.1.5 son vulnerables a directory traversal a través del parámetro 'option' mainfunction.cgi dumpSyslog que permite a un atacante autenticado con acceso a la interfaz de administración web eliminar archivos arbitrarios. Vigor2960 ya no es compatible.
** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-11-22 CVE Reserved
- 2023-11-22 CVE Published
- 2024-08-02 CVE Updated
- 2024-08-02 First Exploit
- 2024-11-28 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 | Product | |
https://www.draytek.com/products/vigor2960 | Product |
URL | Date | SRC |
---|---|---|
https://github.com/xxy1126/Vuln/blob/main/Draytek/4.md | 2024-08-02 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Draytek Search vendor "Draytek" | Vigor2960 Firmware Search vendor "Draytek" for product "Vigor2960 Firmware" | 1.5.1.4 Search vendor "Draytek" for product "Vigor2960 Firmware" and version "1.5.1.4" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2960 Search vendor "Draytek" for product "Vigor2960" | - | - |
Safe
|
Draytek Search vendor "Draytek" | Vigor2960 Firmware Search vendor "Draytek" for product "Vigor2960 Firmware" | 1.5.1.5 Search vendor "Draytek" for product "Vigor2960 Firmware" and version "1.5.1.5" | - |
Affected
| in | Draytek Search vendor "Draytek" | Vigor2960 Search vendor "Draytek" for product "Vigor2960" | - | - |
Safe
|