Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-46586 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sCloudPass parameter at v2x00.cgi. This vulnerability allows attackers… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46588 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at wizfw.cgi. This vulnerability allows attacke… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46550 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the CGIbyFieldName parameter at chglog.cgi. This vulnerability allows atta… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46551 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_Pwd parameter at inet15.cgi. This vulnerability allows attackers … Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46552 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sStRtMskShow parameter at ipstrt.cgi. This vulnerability allows attack… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46553 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ipaddrmsk%d parameter at v2x00.cgi. This vulnerability allows attacker… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46554 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the profname parameter at v2x00.cgi. This vulnerability allows attackers t… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46555 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pb parameter at v2x00.cgi. This vulnerability allows attackers to caus… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46556 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sInRCSecret0 parameter at v2x00.cgi. This vulnerability allows attacke… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46557 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attacke… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 8.8 CVE-2024-44844 DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct… Vigor3900 Firmware No fix yet Fix from $1,9502024-09-06 HIGH 8.8 CVE-2024-44845 DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu… Vigor3900 Firmware No fix yet Fix from $1,9502024-09-06 CRITICAL 9.8 CVE-2023-47254 An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and esca… Vigor167 Firmware No fix yet Fix from $2,3002023-12-09 HIGH 8.1 CVE-2023-6265 ** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'op… Vigor2960 Firmware No fix yet Fix from $1,9502023-11-22 HIGH 7.8 CVE-2023-24229EPSS 7% DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v… Vigor2960 Firmware No fix yet Fix from $1,9502023-03-15 HIGH 8.8 CVE-2023-1162EPSS 26% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an un… Vigor 2960 Firmware No fix yet Fix from $1,9502023-03-03 MEDIUM 6.5 CVE-2023-1163 ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul… Vigor 2960 Firmware No fix yet Fix from $1,6002023-03-03 MEDIUM 5.5 CVE-2023-1009EPSS 16% ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function… Vigor2960 Firmware No fix yet Fix from $1,6002023-02-24 CRITICAL 9.8 CVE-2021-43118EPSS 35% A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a craft… Vigor2960 Firmware No fix yet Fix from $2,3002022-03-29 MEDIUM 5.4 CVE-2020-28968 Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vul… Vigorap 1000c Firmware No fix yet Fix from $1,6002021-10-22 CRITICAL 9.8 CVE-2021-20125 An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect… Vigorconnect No fix yet Fix from $2,3002021-10-13 HIGH 8.8 CVE-2021-20126 Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent … Vigorconnect No fix yet Fix from $1,9502021-10-13 HIGH 8.1 CVE-2021-20127 An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This … Vigorconnect No fix yet Fix from $1,9502021-10-13 HIGH 7.5 CVE-2021-20123 KEVEPSS 75% A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. … Vigorconnect Mitigation only Fix from $1,9502021-10-13 HIGH 7.5 CVE-2021-20124 KEVEPSS 71% A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauth… Vigorconnect Mitigation only Fix from $1,9502021-10-13 HIGH 7.5 CVE-2021-20129 An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs. Vigorconnect No fix yet Fix from $1,9502021-10-13 MEDIUM 5.4 CVE-2021-20128 The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input… Vigorconnect No fix yet Fix from $1,6002021-10-13 HIGH 7.5 CVE-2020-3932 A vulnerable SNMP in Draytek VigorAP910C cannot be disabled, which may cause information leakage. Vigorap 910c Firmware Mitigation only Fix from $1,9502020-04-15 CRITICAL 9.8 CVE-2020-8515 KEVEPSS 100% DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo… Vigor2960 Firmware Mitigation only Fix from $2,3002020-02-01 MEDIUM 6.1 CVE-2019-16533 On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an… Vigor2925 Firmware Mitigation only Fix from $1,6002019-09-20