DrayTek Vigor2960 mainfunction.cgi dumpSyslog 'option' directory traversal
Vulnerability Description
** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'option' parameter allowing an authenticated attacker with access to the web management interface to delete arbitrary files. Vigor2960 is no longer supported.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-6265
Credits & Attribution
No credits recorded in the NVD database.
References
More from DrayTek
View All →Affected Vendor
DrayTek
View all reports →