CVE-2024-41590

moderate-risk
Published 2024-10-03

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.

Do I need to act?

-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.0/10 High
ADJACENT_NETWORK / LOW complexity

Affected Products (20)

Vigor2765 Firmware
Vigor2763 Firmware
Vigor2135 Firmware
Vigor166 Firmware
Vigor3912 Firmware
Vigor1000B Firmware
Vigor165 Firmware
Vigor2962 Firmware
Vigorlte200 Firmware
Vigor2133 Firmware
Vigor2762 Firmware
Vigor2832 Firmware
Vigor2860 Firmware
Vigor2862 Firmware
Vigor2925 Firmware
Vigor2926 Firmware
Vigor2952 Firmware
Vigor3220 Firmware
Vigor2620 Firmware

Affected Vendors

46
/ 100
moderate-risk
Severity 25/34 · High
Exploitability 0/34 · Minimal
Exposure 21/34 · High