CVE detail
CVE-2023-31447 — CVE-2023-31447
Published 2023-08-21 · Modified 2026-06-17 · Vendor draytek · Product vigor2620_firmware · Source nvd
CRITICAL
severity
CVSS-derived band
0.0086
EPSS probability
exploitation probability, 30d
55.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References