Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Vigor3910 Firmware HIGH 7.5
CVE-2024-46586

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sCloudPass parameter at v2x00.cgi. This vulnerability allows attackers…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46588

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allows attacke…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46550

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the CGIbyFieldName parameter at chglog.cgi. This vulnerability allows atta…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46551

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_Pwd parameter at inet15.cgi. This vulnerability allows attackers …

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46552

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sStRtMskShow parameter at ipstrt.cgi. This vulnerability allows attack…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46553

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ipaddrmsk%d parameter at v2x00.cgi. This vulnerability allows attacker…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46554

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the profname parameter at v2x00.cgi. This vulnerability allows attackers t…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46555

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pb parameter at v2x00.cgi. This vulnerability allows attackers to caus…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46556

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sInRCSecret0 parameter at v2x00.cgi. This vulnerability allows attacke…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46557

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attacke…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3900 Firmware HIGH 8.8
CVE-2024-44844

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct…

No fix yet
Fix from $1,950 2024-09-06
Vigor3900 Firmware HIGH 8.8
CVE-2024-44845

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu…

No fix yet
Fix from $1,950 2024-09-06
Vigor167 Firmware CRITICAL 9.8
CVE-2023-47254

An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and esca…

No fix yet
Fix from $2,300 2023-12-09
Vigor2960 Firmware HIGH 8.1
CVE-2023-6265

** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'op…

No fix yet
Fix from $1,950 2023-11-22
Vigor2960 Firmware HIGH 7.8
CVE-2023-24229EPSS 7%

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v…

No fix yet
Fix from $1,950 2023-03-15
Vigor 2960 Firmware HIGH 8.8
CVE-2023-1162EPSS 26%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an un…

No fix yet
Fix from $1,950 2023-03-03
Vigor 2960 Firmware MEDIUM 6.5
CVE-2023-1163

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul…

No fix yet
Fix from $1,600 2023-03-03
Vigor2960 Firmware MEDIUM 5.5
CVE-2023-1009EPSS 16%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function…

No fix yet
Fix from $1,600 2023-02-24
Vigor2960 Firmware CRITICAL 9.8
CVE-2021-43118EPSS 35%

A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a craft…

No fix yet
Fix from $2,300 2022-03-29
Vigorap 1000c Firmware MEDIUM 5.4
CVE-2020-28968

Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vul…

No fix yet
Fix from $1,600 2021-10-22
Vigorconnect CRITICAL 9.8
CVE-2021-20125

An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect…

No fix yet
Fix from $2,300 2021-10-13
Vigorconnect HIGH 8.8
CVE-2021-20126

Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent …

No fix yet
Fix from $1,950 2021-10-13
Vigorconnect HIGH 8.1
CVE-2021-20127

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This …

No fix yet
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20123 KEVEPSS 75%

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. …

Mitigation only
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20124 KEVEPSS 71%

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauth…

Mitigation only
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20129

An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.

No fix yet
Fix from $1,950 2021-10-13
Vigorconnect MEDIUM 5.4
CVE-2021-20128

The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input…

No fix yet
Fix from $1,600 2021-10-13
Vigorap 910c Firmware HIGH 7.5
CVE-2020-3932

A vulnerable SNMP in Draytek VigorAP910C cannot be disabled, which may cause information leakage.

Mitigation only
Fix from $1,950 2020-04-15
Vigor2960 Firmware CRITICAL 9.8
CVE-2020-8515 KEVEPSS 100%

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo…

Mitigation only
Fix from $2,300 2020-02-01
Vigor2925 Firmware MEDIUM 6.1
CVE-2019-16533

On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an…

Mitigation only
Fix from $1,600 2019-09-20