HIGH · 8.0

CVE-2024-41588

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters pas...

Vulnerability Description

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DraytekVigor2620 FirmwareAll versions
DraytekVigor2620-
DraytekVigor2915 Firmware< 4.4.5.3
DraytekVigor2915-
DraytekVigor2866 Firmware< 4.4.5.2
DraytekVigor2866-
DraytekVigor2766 Firmware< 4.4.5.3
DraytekVigor2766-
DraytekVigor2865 Firmware< 4.4.5.2
DraytekVigor2865-
DraytekVigor2765 Firmware< 4.4.5.3
DraytekVigor2765-
DraytekVigor2763 Firmware< 4.4.5.3
DraytekVigor2763-
DraytekVigor2135 Firmware< 4.4.5.3
DraytekVigor2135-
DraytekVigor166 Firmware< 4.2.7
DraytekVigor166-
DraytekVigor3912 Firmware< 4.3.6.1
DraytekVigor3912-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-41588?

CVE-2024-41588 is a vulnerability with a CVSS score of 8.0 (HIGH). The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters pas...

How severe is CVE-2024-41588?

CVE-2024-41588 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-41588?

Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigor2620 Firmware, Draytek Vigor2620, Draytek Vigor2915 Firmware, Draytek Vigor2915, Draytek Vigor2866 Firmware.