Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vigor3900 Firmware HIGH 8.8
CVE-2024-51254

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cace…

Mitigation only
Fix from $1,950 2024-10-31
Vigor3900 Firmware HIGH 8.8
CVE-2024-51258

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunn…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-51298

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel…

Mitigation only
Fix from $2,300 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51257

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertifi…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51296

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace f…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51299

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog …

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51300

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd fun…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51301

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_moni…

Mitigation only
Fix from $1,950 2024-10-30
Vigor3900 Firmware HIGH 8.8
CVE-2024-51304

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search…

Mitigation only
Fix from $1,950 2024-10-30
Vigor2960 Firmware HIGH 8.0
CVE-2024-48074

An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table …

No fix yet
Fix from $1,950 2024-10-28
Vigor3900 Firmware CRITICAL 9.8
CVE-2024-48153

DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subco…

Mitigation only
Fix from $2,300 2024-10-14
Vigor3900 Firmware HIGH 8.0
CVE-2024-46316

DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This …

Mitigation only
Fix from $1,950 2024-10-09
Vigor3912 Firmware CRITICAL 9.8
CVE-2024-41593

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-ext…

Fix: 4.2.7 / 4.3.2.8+
Fix from $2,300 2024-10-03
Vigor3910 Firmware HIGH 8.8
CVE-2024-41589

DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.

Fix: after 4.3.2.6
Fix from $1,950 2024-10-03
Vigor3910 Firmware HIGH 8.0
CVE-2024-41586

A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long…

Fix: after 4.3.2.6
Fix from $1,950 2024-10-03
Vigor2620 Firmware HIGH 8.0
CVE-2024-41588

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, b…

Fix: 4.4.5.2 / 4.4.5.3+
Fix from $1,950 2024-10-03
Vigor2765 Firmware HIGH 8.0
CVE-2024-41590

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POS…

Fix: 4.2.7 / 4.3.2.8+
Fix from $1,950 2024-10-03
Vigor2952 Firmware HIGH 8.0
CVE-2024-41592

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous am…

Fix: 3.9.8.2 / 3.9.8.9+
Fix from $1,950 2024-10-03
Vigor3910 Firmware HIGH 8.0
CVE-2024-41595

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bo…

Fix: after 4.3.2.6
Fix from $1,950 2024-10-03
Vigor2620 Firmware HIGH 8.0
CVE-2024-41596

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and hand…

Fix: 4.4.5.2 / 4.4.5.3+
Fix from $1,950 2024-10-03
Vigor2620 Firmware HIGH 7.5
CVE-2024-41594

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor managem…

Fix: 4.4.5.2 / 4.4.5.3+
Fix from $1,950 2024-10-03
Vigor3910 Firmware MEDIUM 6.8
CVE-2024-41585

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binar…

Fix: after 4.3.2.6
Fix from $1,600 2024-10-03
Vigor2620 Firmware MEDIUM 6.1
CVE-2024-41591

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

Fix: 4.4.5.2 / 4.4.5.3+
Fix from $1,600 2024-10-03
Vigor3910 Firmware MEDIUM 5.4
CVE-2024-41587

Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.

Fix: 4.2.7 / 4.3.2.8+
Fix from $1,600 2024-10-03
Vigor3910 Firmware HIGH 7.5
CVE-2024-46589

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi. This vulnerability allows at…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46590

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. This vulnerability allows attack…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46591

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attackers to…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46592

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. This vulnerability allows att…

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46593

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vulnerability allows attackers …

Mitigation only
Fix from $1,950 2024-09-18
Vigor3910 Firmware HIGH 7.5
CVE-2024-46594

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allows attac…

Mitigation only
Fix from $1,950 2024-09-18