Vulnerability index

Browse CVEs

132 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2024-51254 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cace… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-31 HIGH 8.8 CVE-2024-51258 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunn… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 CRITICAL 9.8 CVE-2024-51298 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-30 HIGH 8.8 CVE-2024-51257 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertifi… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51296 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace f… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51299 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog … Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51300 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd fun… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51301 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_moni… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.8 CVE-2024-51304 In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search… Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-30 HIGH 8.0 CVE-2024-48074 An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table … Vigor2960 Firmware No fix yet Fix from $1,9502024-10-28 CRITICAL 9.8 CVE-2024-48153 DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subco… Vigor3900 Firmware Mitigation only Fix from $2,3002024-10-14 HIGH 8.0 CVE-2024-46316 DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This … Vigor3900 Firmware Mitigation only Fix from $1,9502024-10-09 CRITICAL 9.8 CVE-2024-41593 DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-ext… Vigor3912 Firmware 4.2.7 / 4.3.2.8+ Fix from $2,3002024-10-03 HIGH 8.8 CVE-2024-41589 DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. Vigor3910 Firmware after 4.3.2.6 Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-41586 A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long… Vigor3910 Firmware after 4.3.2.6 Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-41588 The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, b… Vigor2620 Firmware 4.4.5.2 / 4.4.5.3+ Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-41590 Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POS… Vigor2765 Firmware 4.2.7 / 4.3.2.8+ Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-41592 DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous am… Vigor2952 Firmware 3.9.8.2 / 3.9.8.9+ Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-41595 DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bo… Vigor3910 Firmware after 4.3.2.6 Fix from $1,9502024-10-03 HIGH 8.0 CVE-2024-41596 Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and hand… Vigor2620 Firmware 4.4.5.2 / 4.4.5.3+ Fix from $1,9502024-10-03 HIGH 7.5 CVE-2024-41594 An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor managem… Vigor2620 Firmware 4.4.5.2 / 4.4.5.3+ Fix from $1,9502024-10-03 MEDIUM 6.8 CVE-2024-41585 DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binar… Vigor3910 Firmware after 4.3.2.6 Fix from $1,6002024-10-03 MEDIUM 6.1 CVE-2024-41591 DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS. Vigor2620 Firmware 4.4.5.2 / 4.4.5.3+ Fix from $1,6002024-10-03 MEDIUM 5.4 CVE-2024-41587 Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6. Vigor3910 Firmware 4.2.7 / 4.3.2.8+ Fix from $1,6002024-10-03 HIGH 7.5 CVE-2024-46589 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sIpv6AiccuUser parameter at inetipv6.cgi. This vulnerability allows at… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46590 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. This vulnerability allows attack… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46591 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attackers to… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46592 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. This vulnerability allows att… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46593 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the trapcomm parameter at cgiswm.cgi. This vulnerability allows attackers … Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18 HIGH 7.5 CVE-2024-46594 Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the saveVPNProfile parameter at v2x00.cgi. This vulnerability allows attac… Vigor3910 Firmware Mitigation only Fix from $1,9502024-09-18