CVE-2022-50994

8.1

DrayTek · Vigor 2960

DrayTek Vigor 2960 firmware prior to 1.5.1.4 contains an OS command injection vulnerability in the CGI login handler, allowing remote attackers to achieve remote code execution.

Executive summary

An OS command injection vulnerability in DrayTek Vigor 2960 firmware prior to version 1.5.1.4 allows unauthenticated attackers to achieve remote code execution with web server privileges.

Vulnerability

This is an OS Command Injection flaw (CWE-78) residing in the CGI login handler and the otp_check.sh script. Attackers can inject shell metacharacters into the formpassword parameter, requiring knowledge of a valid username with MOTP authentication enabled and unauthenticated remote access.

Business impact

A successful exploit grants an attacker complete remote control over the affected network device with web server privileges, potentially leading to total compromise of network traffic and internal asset exposure. With a CVSS score of 8.1, the severity is high, highlighting a significant risk of unauthorized access, lateral movement, and severe system downtime.

Remediation

Immediate Action: Update the DrayTek Vigor 2960 firmware to version 1.5.1.4 or later using the official vendor security update.

Proactive Monitoring: Monitor device access logs for unusual authentication patterns, repeated login handler anomalies, and unexpected shell execution processes.

Compensating Controls: Restrict administrative management interfaces to trusted internal networks or VPNs to limit exposure to potential remote attackers.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical nature of remote code execution vulnerabilities on network infrastructure devices, organizations utilizing the DrayTek Vigor 2960 must apply the firmware update to version 1.5.1.4 immediately. Securing administrative interfaces and auditing device logs will further mitigate the risk of exploitation.

More DrayTek CVEs

Sources