OS Command Injection Vulnerability in DrayTek Vigor 300B Web Management Interface
CVE-2026-3040
Key Information:
- Vendor
Draytek
- Status
- Vendor
- CVE Published:
- 23 February 2026
Badges
What is CVE-2026-3040?
A vulnerability exists in the DrayTek Vigor 300B's web management interface, specifically within the cgiGetFile function of the /cgi-bin/mainfunction.cgi/uploadlangs component. This security flaw allows for OS command injection through the manipulation of the File parameter, enabling remote attackers to execute arbitrary commands. The affected product version, 1.5.1.6, is no longer supported by DrayTek, which has confirmed it will not issue a patch for this vulnerability. As such, users should be aware of the risks associated with using this EoL product and take appropriate measures to secure their networks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Vigor 300B 1.5.1.0
Vigor 300B 1.5.1.1
Vigor 300B 1.5.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved