Release date:
Updated on:
Affected Systems:
Draytek Vigor 2700 2.8.3
Description:
--------------------------------------------------------------------------------
Bugtraq id: 63271
CVE (CAN) ID: CVE-2013-5703
The DrayTek Vigor 2700 series are ADSL2/2 + Firewall routers.
The remote command injection vulnerability exists in DrayTek Vigor 2700 ADSL Router Firmware Version 2.8.3 and other versions. After successful exploitation, arbitrary commands can be executed in the context of the affected device.
<* Source: Juraj Kosik
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Draytek
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.draytek.co.uk
Http://www.draytek.com/.upload/Demo/Vigor2700Ge_2.8.3/