DrayTek vendor intelligence

DrayTek Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting DrayTek products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.

Total KEVs
6
Known exploited vulnerabilities affecting DrayTek products
In CISA KEV
5
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited CVEs absent from CISA KEV
Sensor Observed
1
DrayTek KEV with sensor-observed exploitation activity

The catalog gap matters for DrayTek exposure

One of the six exploited DrayTek CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 17% of this vendor portfolio.

83%
Covered by CISA
17%
Beyond CISA
4
Product families

Attested DrayTek CVEs

Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.

How exploitation is verified
CVE / description Product Confidence CISA KEV Added
CVE-2024-12987

DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

Vigor2960, Vigor300B Confirmed In CISA 16 May 2025
CVE-2020-8515

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as...

Vigor2960, Vigor3900, Vigor300B Confirmed In CISA 03 Nov 2021
CVE-2021-20123

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet...

Draytek VigorConnect Confirmed In CISA 03 Sep 2024
CVE-2021-20124

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An...

Draytek VigorConnect Confirmed In CISA 03 Sep 2024
CVE-2020-15415

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via...

Vigor3900, Vigor2960, Vigor300B Confirmed In CISA 30 Sep 2024
CVE-2020-10826

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via...

Vigor3900, Vigor2960, Vigor300B High Beyond CISA 26 Mar 2020

Showing 6 of 6 DrayTek known exploited vulnerabilities.

Recurring weakness patterns

Neutralization, limitation, and neutralization account for seven mapped occurrences across this DrayTek KEV portfolio.

Browse all KEVs →

Early warning alerts

Get alerts on high-impact exploitation

Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.

Occasional high-impact alerts. Unsubscribe anytime. See our Privacy Policy.