CyberMax
Home › Exploited CVEs

DrayTek known exploited vulnerabilities

CISA KEV catalog 2026.09.25 (1,726 CVEs) with FIRST EPSS scores from 2026-09-27.

CISA lists 5 DrayTek CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-05-15), and 0 are known to be used in ransomware campaigns.

DrayTek CVEs added to CISA KEV per year
2021: 1202112024: 3202432025: 120251

Year = when CISA added the CVE to the catalog (KEV started in November 2021).

Patch first: highest EPSS right now

EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.

Most affected DrayTek products

Multiple Vigor Routers (2), VigorConnect (2), Vigor Routers (1).

All DrayTek CVEs in KEV

CVEProductFlawAddedFederal dueEPSSRansomware
CVE-2024-12987Vigor RoutersVigor Routers OS Command Injection2025-05-152025-06-0598.1%–
CVE-2020-15415Multiple Vigor RoutersMultiple Vigor Routers OS Command Injection2024-09-302024-10-2184.5%–
CVE-2021-20124VigorConnectDraytek VigorConnect Path Traversal2024-09-032024-09-2496.3%–
CVE-2021-20123VigorConnectDraytek VigorConnect Path Traversal2024-09-032024-09-2490.2%–
CVE-2020-8515Multiple Vigor RoutersMultiple Vigor Routers Web Management Page2021-11-032022-05-03100.0%–
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.

Read next: Which CVEs to patch first this week · All vendors