DrayTek vendor intelligence
DrayTek Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting DrayTek products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 6
- Known exploited vulnerabilities affecting DrayTek products
- In CISA KEV
- 5
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 1
- DrayTek KEV with sensor-observed exploitation activity
The catalog gap matters for DrayTek exposure
One of the six exploited DrayTek CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 17% of this vendor portfolio.
- 83%
- Covered by CISA
- 17%
- Beyond CISA
- 4
- Product families
Attested DrayTek CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-12987
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection |
Vigor2960, Vigor300B | Confirmed | In CISA | 16 May 2025 |
|
CVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as... |
Vigor2960, Vigor3900, Vigor300B | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-20123
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet... |
Draytek VigorConnect | Confirmed | In CISA | 03 Sep 2024 |
|
CVE-2021-20124
A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An... |
Draytek VigorConnect | Confirmed | In CISA | 03 Sep 2024 |
|
CVE-2020-15415
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via... |
Vigor3900, Vigor2960, Vigor300B | Confirmed | In CISA | 30 Sep 2024 |
|
CVE-2020-10826
/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via... |
Vigor3900, Vigor2960, Vigor300B | High | Beyond CISA | 26 Mar 2020 |
No DrayTek CVEs match this search or filter.
Showing 6 of 6 DrayTek known exploited vulnerabilities.
Recurring weakness patterns
Neutralization, limitation, and neutralization account for seven mapped occurrences across this DrayTek KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.