CVE-2023-1163

A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4 and classified as problematic. Affected by this vulnerability is the function sub_1DA58 of the file mainfunction.cgi. The manipulation leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222259.
References
Link Resource
https://github.com/xxy1126/Vuln/blob/main/Draytek/3.md Exploit
https://vuldb.com/?id.222259 Third Party Advisory VDB Entry
https://vuldb.com/?ctiid.222259 Permissions Required Third Party Advisory VDB Entry
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:draytek:vigor_2960_firmware:1.5.1.4:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor_2960:-:*:*:*:*:*:*:*

Information

Published : 2023-03-02 23:15

Updated : 2023-03-10 11:00


NVD link : CVE-2023-1163

Mitre link : CVE-2023-1163


JSON object : View

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Advertisement

dedicated server usa

Products Affected

draytek

  • vigor_2960_firmware
  • vigor_2960