Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vigor300b Firmware CRITICAL 9.8
CVE-2020-10823

A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allo…

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Vigor300b Firmware CRITICAL 9.8
CVE-2020-10824

A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 a…

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Vigor300b Firmware CRITICAL 9.8
CVE-2020-10825

A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices …

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Vigor300b Firmware CRITICAL 9.8
CVE-2020-10826EPSS 39%

/cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injection via a …

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Vigor300b Firmware CRITICAL 9.8
CVE-2020-10827EPSS 21%

A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exe…

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Vigor300b Firmware CRITICAL 9.8
CVE-2020-10828EPSS 21%

A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve code exe…

Fix: 1.5.1+
Fix from $2,300 2020-03-26
Vigor2960 Firmware CRITICAL 9.8
CVE-2020-8515 KEVEPSS 100%

DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as roo…

Mitigation only
Fix from $2,300 2020-02-01
Vigor2925 Firmware MEDIUM 6.1
CVE-2019-16533

On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an…

Mitigation only
Fix from $1,600 2019-09-20
Vigor2925 Firmware MEDIUM 6.1
CVE-2019-16534

On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life produ…

Mitigation only
Fix from $1,600 2019-09-20
Vigorap 910c Firmware HIGH 8.8
CVE-2017-11649

Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack…

No fix yet
Fix from $1,950 2018-03-07
Vigorap 910c Firmware MEDIUM 6.1
CVE-2017-11650

Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitr…

No fix yet
Fix from $1,600 2018-03-07
Vigor 2700 Router Firmware MEDIUM 6.8
CVE-2013-5703

The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted…

Mitigation only
Fix from $1,600 2013-10-22