{ "id": "CVE-2023-31447", "sourceIdentifier": "cve@mitre.org", "published": "2023-08-21T17:15:46.847", "lastModified": "2023-08-21T17:15:46.847", "vulnStatus": "Received", "descriptions": [ { "lang": "en", "value": "user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code." } ], "metrics": {}, "references": [ { "url": "https://draytek.com", "source": "cve@mitre.org" }, { "url": "https://gist.github.com/rrrrrrri/013c9eef64b265af4163478bfcf29ff4", "source": "cve@mitre.org" } ] }