DrayTek known exploited vulnerabilities
CISA lists 5 DrayTek CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2025-05-15), and 0 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2020-8515 (Multiple Vigor Routers): EPSS 100.0%, added 2021-11-03
- CVE-2024-12987 (Vigor Routers): EPSS 98.1%, added 2025-05-15
- CVE-2021-20124 (VigorConnect): EPSS 96.3%, added 2024-09-03
- CVE-2021-20123 (VigorConnect): EPSS 90.2%, added 2024-09-03
- CVE-2020-15415 (Multiple Vigor Routers): EPSS 84.5%, added 2024-09-30
Most affected DrayTek products
Multiple Vigor Routers (2), VigorConnect (2), Vigor Routers (1).
All DrayTek CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2024-12987 | Vigor Routers | Vigor Routers OS Command Injection | 2025-05-15 | 2025-06-05 | 98.1% | – |
| CVE-2020-15415 | Multiple Vigor Routers | Multiple Vigor Routers OS Command Injection | 2024-09-30 | 2024-10-21 | 84.5% | – |
| CVE-2021-20124 | VigorConnect | Draytek VigorConnect Path Traversal | 2024-09-03 | 2024-09-24 | 96.3% | – |
| CVE-2021-20123 | VigorConnect | Draytek VigorConnect Path Traversal | 2024-09-03 | 2024-09-24 | 90.2% | – |
| CVE-2020-8515 | Multiple Vigor Routers | Multiple Vigor Routers Web Management Page | 2021-11-03 | 2022-05-03 | 100.0% | – |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors