HIGH · 8.0

CVE-2024-41590

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor3...

Vulnerability Description

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DraytekVigor2765 Firmware< 4.4.5.3
DraytekVigor2765-
DraytekVigor2763 Firmware< 4.4.5.3
DraytekVigor2763-
DraytekVigor2135 Firmware< 4.4.5.3
DraytekVigor2135-
DraytekVigor166 Firmware< 4.2.7
DraytekVigor166-
DraytekVigor3912 Firmware< 4.3.6.1
DraytekVigor3912-
DraytekVigor1000B Firmware< 4.3.2.8
DraytekVigor1000B-
DraytekVigor165 Firmware< 4.2.7
DraytekVigor165-
DraytekVigor3910 Firmware< 4.3.2.8
DraytekVigor3910-
DraytekVigor2962 Firmware< 4.3.2.8
DraytekVigor2962-
DraytekVigorlte200 FirmwareAll versions
DraytekVigorlte200-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-41590?

CVE-2024-41590 is a vulnerability with a CVSS score of 8.0 (HIGH). Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor3...

How severe is CVE-2024-41590?

CVE-2024-41590 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-41590?

Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigor2765 Firmware, Draytek Vigor2765, Draytek Vigor2763 Firmware, Draytek Vigor2763, Draytek Vigor2135 Firmware.