Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vigor300b Firmware HIGH 7.2
CVE-2026-3040EPSS 9%

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload…

Fix: after 1.5.1.6
Fix from $1,950 2026-02-23
Vigor3912 Firmware CRITICAL 9.8
CVE-2024-51138

Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133…

Fix: 3.9.8.3 / 3.9.9.1+
Fix from $2,300 2025-02-27
Vigor2620 Firmware CRITICAL 9.8
CVE-2024-51139

Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and…

Fix: 3.9.8.3 / 3.9.9.1+
Fix from $2,300 2025-02-27
Vigor166 Firmware HIGH 8.8
CVE-2024-41334

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9…

Fix: 3.9.7 / 3.9.8+
Fix from $1,950 2025-02-27
Vigor165 Firmware HIGH 8.8
CVE-2024-41339

An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vi…

Fix: 3.9.8 / 3.9.8.9+
Fix from $1,950 2025-02-27
Vigor165 Firmware HIGH 8.4
CVE-2024-41340

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 pri…

Fix: 3.9.8 / 3.9.8.9+
Fix from $1,950 2025-02-27
Vigor165 Firmware HIGH 7.5
CVE-2024-41338

A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, V…

Fix: 3.9.7 / 3.9.8.8+
Fix from $1,950 2025-02-27
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12987 KEVEPSS 98%

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file …

Mitigation only
Fix from $2,300 2024-12-27
Vigor300b Firmware CRITICAL 9.8
CVE-2024-12986EPSS 33%

A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown…

Fix: 1.5.1.5+
Fix from $2,300 2024-12-27
Vigor3900 Firmware HIGH 8.0
CVE-2024-45885

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45887

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45888

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45889

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45890

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cg…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45891

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45893

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45882

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-45884

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51246

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51249

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51251

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware HIGH 8.0
CVE-2024-51253

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP func…

Mitigation only
Fix from $1,950 2024-11-04
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51252

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun…

No fix yet
Fix from $2,300 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51244

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec fun…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51245

In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_tabl…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51247

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo func…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware HIGH 8.8
CVE-2024-51248

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow f…

No fix yet
Fix from $1,950 2024-11-01
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51255

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_…

Mitigation only
Fix from $2,300 2024-10-31
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51260

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_proc…

Mitigation only
Fix from $2,300 2024-10-31
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51259

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cac…

Mitigation only
Fix from $2,300 2024-10-31