CVE-2020-8515
Multiple DrayTek Vigor Routers Web Management Page Vulnerability
- Published
- Feb 1, 2020
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Mar 30, 2020
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has been fixed in Vigor3900/2960/300B v1.5.1.
Sources
4- CVE-2020-8515Exploit
Proof-of-concept exploit for CVE-2020-8515 command injection in Draytek routers. Includes automated exploitation, reverse shell delivery, and integration with nuclei scanning templates.
- nmap_draytek_rceScanner
nmap script to detect CVE-2020-8515 on Draytek Devices
Proof-of-concept exploit for CVE-2020-8515 targeting DrayTek routers with remote code execution via unauthenticated HTTP request.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.