CVE-2022-50994 | DrayTek Vigor 2960 up to 1.5.1.4 otp_check.sh formpassword os command injection
A vulnerability was found in DrayTek Vigor 2960 up to 1.5.1.4. It has been declared as critical. Affected by this issue is some unknown functionality of the file otp_check.sh. The manipulation of the argument formpassword results in os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2022-50994. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.