Vigor 2960 Draytek Vigor 2960

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Draytek Vigor 2960.

By the Year

In 2026 there have been 1 vulnerability in Draytek Vigor 2960 with an average score of 8.1 out of ten.

Year Vulnerabilities Average Score
2026 1 8.10

It may take a day or so for new Vigor 2960 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Draytek Vigor 2960 Security Vulnerabilities

DrayTek Vigor 2960 OS Cmd Injection via formpassword (pre1.5.1.4)
CVE-2022-50994 8.1 - High - May 08, 2026

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login handler that allows unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter. Attackers can exploit unsanitized input passed to the otp_check.sh script to achieve remote code execution with web server privileges. Exploitation requires knowledge of a valid username and that the target account has MOTP authentication enabled.

Shell injection

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Draytek Vigor 2960 or by Draytek? Click the Watch button to subscribe.

Draytek
Vendor

subscribe