CVE-2023-6265

** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.5:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:43

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.1
v2 : unknown
v3 : 6.5
References () https://github.com/xxy1126/Vuln/blob/main/Draytek/4.md - Exploit () https://github.com/xxy1126/Vuln/blob/main/Draytek/4.md - Exploit
References () https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 - Product () https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 - Product
References () https://www.draytek.com/products/vigor2960/ - Product () https://www.draytek.com/products/vigor2960/ - Product

19 Dec 2023, 21:15

Type Values Removed Values Added
Summary Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported. ** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.

30 Nov 2023, 05:04

Type Values Removed Values Added
References () https://www.draytek.com/products/vigor2960/ - () https://www.draytek.com/products/vigor2960/ - Product
References () https://github.com/xxy1126/Vuln/blob/main/Draytek/4.md - () https://github.com/xxy1126/Vuln/blob/main/Draytek/4.md - Exploit
References () https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 - () https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 - Product
CWE CWE-22
CPE cpe:2.3:h:draytek:vigor2960:-:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.5:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2960_firmware:1.5.1.4:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
First Time Draytek vigor2960 Firmware
Draytek vigor2960
Draytek

27 Nov 2023, 23:15

Type Values Removed Values Added
References
  • () https://www.draytek.com/about/newsroom/2021/2021/end-of-life-notification-vigor2960 -

22 Nov 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-22 20:15

Updated : 2024-11-21 08:43


NVD link : CVE-2023-6265

Mitre link : CVE-2023-6265

CVE.ORG link : CVE-2023-6265


JSON object : View

Products Affected

draytek

  • vigor2960_firmware
  • vigor2960
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')