Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vigor3900 Firmware HIGH 8.8
CVE-2024-44844

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command funct…

No fix yet
Fix from $1,950 2024-09-06
Vigor3900 Firmware HIGH 8.8
CVE-2024-44845

DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string fu…

No fix yet
Fix from $1,950 2024-09-06
Vigor300b Firmware HIGH 8.0
CVE-2024-43027

DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to conta…

Fix: 1.5.1.5+
Fix from $1,950 2024-08-21
Vigor3910 Firmware HIGH 7.5
CVE-2024-23721

A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the fu…

Fix: after 4.3.2.5
Fix from $1,950 2024-03-20
Vigor167 Firmware CRITICAL 9.8
CVE-2023-47254

An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and esca…

No fix yet
Fix from $2,300 2023-12-09
Vigor2960 Firmware HIGH 8.1
CVE-2023-6265

** UNSUPPORTED WHEN ASSIGNED ** Draytek Vigor2960 v1.5.1.4 and v1.5.1.5 are vulnerable to directory traversal via the mainfunction.cgi dumpSyslog 'op…

No fix yet
Fix from $1,950 2023-11-22
Vigor2620 Firmware CRITICAL 9.8
CVE-2023-31447

user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to m…

Fix: 3.9.8.4+
Fix from $2,300 2023-08-21
Myvigor CRITICAL 9.8
CVE-2023-33778

Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.6.7, and …

Fix: 2.3.2 / 2.6.7+
Fix from $2,300 2023-06-01
Vigor2960 Firmware HIGH 7.8
CVE-2023-24229EPSS 7%

DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to inject operating system commands v…

No fix yet
Fix from $1,950 2023-03-15
Vigor2860 Firmware MEDIUM 6.1
CVE-2023-23313

Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web applica…

Fix: 3.9.4+
Fix from $1,600 2023-03-03
Vigor 2960 Firmware HIGH 8.8
CVE-2023-1162EPSS 26%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is an un…

No fix yet
Fix from $1,950 2023-03-03
Vigor 2960 Firmware MEDIUM 6.5
CVE-2023-1163

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5 and classified as critical. Affected by this vul…

No fix yet
Fix from $1,600 2023-03-03
Vigor2960 Firmware MEDIUM 5.5
CVE-2023-1009EPSS 16%

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as critical has been found in DrayTek Vigor 2960 1.5.1.4/1.5.1.5. Affected is the function…

No fix yet
Fix from $1,600 2023-02-24
Vigor3910 Firmware CRITICAL 9.8
CVE-2022-32548EPSS 34%

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer over…

Fix: 4.3.1.1 / 4.4.0+
Fix from $2,300 2022-08-29
Vigor2960 Firmware CRITICAL 9.8
CVE-2021-42911

A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in the mainfu…

Fix: after 1.5.1.3
Fix from $2,300 2022-03-29
Vigor2960 Firmware CRITICAL 9.8
CVE-2021-43118EPSS 35%

A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a craft…

No fix yet
Fix from $2,300 2022-03-29
Vigorap 1000c Firmware MEDIUM 5.4
CVE-2020-28968

Draytek VigorAP 1000C contains a stored cross-site scripting (XSS) vulnerability in the RADIUS Setting - RADIUS Server Configuration module. This vul…

No fix yet
Fix from $1,600 2021-10-22
Vigorconnect CRITICAL 9.8
CVE-2021-20125

An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek VigorConnect…

No fix yet
Fix from $2,300 2021-10-13
Vigorconnect HIGH 8.8
CVE-2021-20126

Draytek VigorConnect 1.6.0-B3 lacks cross-site request forgery protections and does not sufficiently verify whether a well-formed, valid, consistent …

No fix yet
Fix from $1,950 2021-10-13
Vigorconnect HIGH 8.1
CVE-2021-20127

An arbitrary file deletion vulnerability exists in the file delete functionality of the Html5Servlet endpoint of Draytek VigorConnect 1.6.0-B3. This …

No fix yet
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20123 KEVEPSS 75%

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet endpoint. …

Mitigation only
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20124 KEVEPSS 71%

A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint. An unauth…

Mitigation only
Fix from $1,950 2021-10-13
Vigorconnect HIGH 7.5
CVE-2021-20129

An information disclosure vulnerability exists in Draytek VigorConnect 1.6.0-B3, allowing an unauthenticated attacker to export system logs.

No fix yet
Fix from $1,950 2021-10-13
Vigorconnect MEDIUM 5.4
CVE-2021-20128

The Profile Name field in the floor plan (Network Menu) page in Draytek VigorConnect 1.6.0-B3 was found to be vulnerable to stored XSS, as user input…

No fix yet
Fix from $1,600 2021-10-13
Vigor2960 Firmware HIGH 8.8
CVE-2020-19664EPSS 5%

DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.

Fix: after 1.5.1
Fix from $1,950 2020-12-31
Vigor3900 Firmware CRITICAL 9.8
CVE-2020-15415 KEVEPSS 85%

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell …

Fix: 1.5.1+
Fix from $2,300 2020-06-30
Vigor300b Firmware CRITICAL 9.8
CVE-2020-14473

Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.

Fix: 1.5.1.1+
Fix from $2,300 2020-06-24
Vigor300b Firmware CRITICAL 9.8
CVE-2020-14472

On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file.

Fix: 1.5.1.1+
Fix from $2,300 2020-06-24
Vigor300b Firmware CRITICAL 9.8
CVE-2020-14993EPSS 5%

A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbitrary code…

Fix: 1.5.1.1+
Fix from $2,300 2020-06-23
Vigorap 910c Firmware HIGH 7.5
CVE-2020-3932

A vulnerable SNMP in Draytek VigorAP910C cannot be disabled, which may cause information leakage.

Mitigation only
Fix from $1,950 2020-04-15