Critical severity9.8NVD Advisory· Published Dec 9, 2023· Updated Jun 17, 2026
CVE-2023-47254
CVE-2023-47254
Description
An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:draytek:vigor167_firmware:5.2.2:*:*:*:*:*:*:*
- DrayTek/Vigor167description
Patches
Vulnerability mechanics
References
2- www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2023-023.txtnvdExploitThird Party Advisory
- www.syss.de/pentest-blog/command-injection-via-cli-des-draytek-vigor167-syss-2023-023nvdThird Party Advisory
News mentions
0No linked articles in our index yet.