The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Oct 2024 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Draytek
Draytek vigor3910 Firmware |
|
Weaknesses | CWE-120 | |
CPEs | cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Draytek
Draytek vigor3910 Firmware |
|
Metrics |
cvssV3_1
|
Thu, 03 Oct 2024 18:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function. | |
References |
|
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2024-10-03T00:00:00
Updated: 2024-10-04T19:09:42.672Z
Reserved: 2024-07-18T00:00:00
Link: CVE-2024-41588
Vulnrichment
Updated: 2024-10-04T19:09:33.217Z
NVD
Status : Undergoing Analysis
Published: 2024-10-03T19:15:04.363
Modified: 2024-10-07T19:37:15.063
Link: CVE-2024-41588
Redhat
No data.