Loading HuntDB...

GHSA-5gfv-6mr8-g7x2

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.

Related CVEs

Key Information

GHSA ID
GHSA-5gfv-6mr8-g7x2
Published
November 22, 2023 9:31 PM
Last Modified
March 21, 2024 3:35 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.