Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-3040EPSS 9% A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/upload… Vigor300b Firmware after 1.5.1.6 Fix from $1,9502026-02-23 CRITICAL 9.8 CVE-2024-51138 Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133… Vigor3912 Firmware 3.9.8.3 / 3.9.9.1+ Fix from $2,3002025-02-27 CRITICAL 9.8 CVE-2024-51139 Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and… Vigor2620 Firmware 3.9.8.3 / 3.9.9.1+ Fix from $2,3002025-02-27 HIGH 8.8 CVE-2024-41334 Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9… Vigor166 Firmware 3.9.7 / 3.9.8+ Fix from $1,9502025-02-27 HIGH 8.8 CVE-2024-41339 An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vi… Vigor165 Firmware 3.9.8 / 3.9.8.9+ Fix from $1,9502025-02-27 HIGH 8.4 CVE-2024-41340 An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 pri… Vigor165 Firmware 3.9.8 / 3.9.8.9+ Fix from $1,9502025-02-27 HIGH 7.5 CVE-2024-41338 A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, V… Vigor165 Firmware 3.9.7 / 3.9.8.8+ Fix from $1,9502025-02-27 CRITICAL 9.8 CVE-2024-12987 KEVEPSS 98% A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file … Vigor300b Firmware Mitigation only Fix from $2,3002024-12-27 CRITICAL 9.8 CVE-2024-12986EPSS 33% A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown… Vigor300b Firmware 1.5.1.5+ Fix from $2,3002024-12-27 HIGH 8.0 CVE-2024-45885 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45887 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45888 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45889 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45890 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cg… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45891 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45893 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45882 DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-45884 DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `c… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51246 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51249 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51251 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 HIGH 8.0 CVE-2024-51253 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP func… Vigor3900 Firmware Mitigation only Fix from $1,9502024-11-04 CRITICAL 9.8 CVE-2024-51252 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore fun… Vigor3900 Firmware No fix yet Fix from $2,3002024-11-01 HIGH 8.8 CVE-2024-51244 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec fun… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-51245 In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_tabl… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-51247 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo func… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 HIGH 8.8 CVE-2024-51248 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow f… Vigor3900 Firmware No fix yet Fix from $1,9502024-11-01 CRITICAL 9.8 CVE-2024-51255 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-31 CRITICAL 9.8 CVE-2024-51260 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_proc… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-31 CRITICAL 9.8 CVE-2024-51259 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cac… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-31