Draytek manufactures a widely deployed line of business-grade networking appliances and routers, particularly its Vigor series, which are prominent fixtures in small-to-medium enterprise and branch-office environments globally. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, driven by the internet-facing and management-accessible nature of these devices. The exposure recurs across the Vigor product line through firmware-level weakness classes including buffer overflows, OS and command injection, cross-site scripting, and out-of-bounds writes, reflecting the memory-safety and input-handling challenges inherent to embedded networking appliances. Defenders should prioritize inventory and patching of exposed Vigor instances, as these devices often sit at network perimeters with limited operational constraints on update cycles. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Draytek over time
Signals from CVEs in this vendor scope (135 CVEs).
135 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8515CRITICAL DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via | Feb 1, 2020 | 9.8 | 98 | YES | YES |
CVE-2024-12987CRITICAL A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcf | Dec 27, 2024 | 9.8 | 97 | YES | YES |
CVE-2020-15415CRITICAL On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename wh | Jun 30, 2020 | 9.8 | 97 | YES | YES |
CVE-2021-20123HIGH A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. An unauthenticated attacker cou | Oct 13, 2021 | 7.5 | 94 | YES | YES |
CVE-2021-20124HIGH A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could levera | Oct 13, 2021 | 7.5 | 93 | YES | YES |
CVE-2020-10826CRITICAL /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a remote HTTP request in DEBUG mo | Mar 26, 2020 | 9.8 | 51 | NO | NO |
CVE-2022-32548CRITICAL An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or passwo | Aug 29, 2022 | 9.8 | 50 | NO | NO |
CVE-2021-43118CRITICAL A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malf | Mar 29, 2022 | 9.8 | 49 | NO | NO |
CVE-2024-12986CRITICAL A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bi | Dec 27, 2024 | 9.8 | 48 | NO | NO |
CVE-2023-1162HIGH ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an unknown function of the file main | Mar 3, 2023 | 8.8 | 40 | NO | NO |
Signals from CVEs in this vendor scope (135 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Draytek.
Media articles that mention a CVE ID that affects a product developed by Draytek — matched by CVE ID, not by vendor name.