HIGH · 8.0

CVE-2024-41596

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

Vulnerability Description

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

CVSS Score

8.0

HIGH

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DraytekVigor2620 FirmwareAll versions
DraytekVigor2620-
DraytekVigor2915 Firmware< 4.4.5.3
DraytekVigor2915-
DraytekVigor2866 Firmware< 4.4.5.2
DraytekVigor2866-
DraytekVigor2766 Firmware< 4.4.5.3
DraytekVigor2766-
DraytekVigor2865 Firmware< 4.4.5.2
DraytekVigor2865-
DraytekVigor2765 Firmware< 4.4.5.3
DraytekVigor2765-
DraytekVigor2763 Firmware< 4.4.5.3
DraytekVigor2763-
DraytekVigor2135 Firmware< 4.4.5.3
DraytekVigor2135-
DraytekVigor166 Firmware< 4.2.7
DraytekVigor166-
DraytekVigor3912 Firmware< 4.3.6.1
DraytekVigor3912-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-41596?

CVE-2024-41596 is a vulnerability with a CVSS score of 8.0 (HIGH). Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.

How severe is CVE-2024-41596?

CVE-2024-41596 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-41596?

Check the references section above for vendor advisories and patch information. Affected products include: Draytek Vigor2620 Firmware, Draytek Vigor2620, Draytek Vigor2915 Firmware, Draytek Vigor2915, Draytek Vigor2866 Firmware.