Vendor

DrayTek

As of , 5 DrayTek vulnerabilities are on CISA's list of exploited vulnerabilities; 0 were added in 2026. Patch first: CVE-2024-12987.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2024-12987OS Command InjectionDrayTek Vigor RoutersPatch this weekEPSS 0.980.98
2CVE-2020-15415OS Command InjectionDrayTek Multiple Vigor RoutersPatch this weekEPSS 0.840.84
3CVE-2021-20123Path TraversalDrayTek VigorConnectPatch this weekEPSS 0.900.90
4CVE-2021-20124Path TraversalDrayTek VigorConnectPatch this weekEPSS 0.960.96
5CVE-2020-8515Multiple DrayTek Vigor Routers Web Management PageDrayTek Multiple Vigor RoutersPatch this weekEPSS 0.990.99

Products

  • Multiple Vigor Routers2 entries
  • VigorConnect2 entries
  • Vigor Routers1 entry

Added each year

1232021: 1120212022: nonenone20222023: nonenone20232024: 3320242025: 1120252026: nonenone2026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20211
2022none
2023none
20243
20251
2026none

Used in ransomware