### [CVE-2020-10824](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10824)



### Description
A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code execution via a remote HTTP request (issue 2 of 3).
### POC
#### Reference
- https://slashd.ga/2020/03/draytek-vulnerabilities/
#### Github
No PoCs found on GitHub currently.