Description
DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.
Published: 2024-10-03
Score: 8 High
EPSS: 1.9% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 03 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Draytek vigor1000b
Draytek vigor1000b Firmware
Draytek vigor165
Draytek vigor165 Firmware
Draytek vigor166
Draytek vigor166 Firmware
Draytek vigor2133
Draytek vigor2133 Firmware
Draytek vigor2135
Draytek vigor2135 Firmware
Draytek vigor2620
Draytek vigor2620 Firmware
Draytek vigor2762
Draytek vigor2762 Firmware
Draytek vigor2763
Draytek vigor2763 Firmware
Draytek vigor2765
Draytek vigor2765 Firmware
Draytek vigor2766
Draytek vigor2766 Firmware
Draytek vigor2832
Draytek vigor2832 Firmware
Draytek vigor2860
Draytek vigor2860 Firmware
Draytek vigor2862
Draytek vigor2862 Firmware
Draytek vigor2865
Draytek vigor2865 Firmware
Draytek vigor2866
Draytek vigor2866 Firmware
Draytek vigor2915
Draytek vigor2915 Firmware
Draytek vigor2925
Draytek vigor2925 Firmware
Draytek vigor2926
Draytek vigor2926 Firmware
Draytek vigor2952
Draytek vigor2952 Firmware
Draytek vigor2962
Draytek vigor2962 Firmware
Draytek vigor3220
Draytek vigor3220 Firmware
Draytek vigor3912
Draytek vigor3912 Firmware
Draytek vigorlte200
Draytek vigorlte200 Firmware
CPEs cpe:2.3:h:draytek:vigor1000b:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor165:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor166:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2133:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2135:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2620:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2762:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2763:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2765:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2766:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2832:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2860:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2862:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2865:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2866:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2915:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2925:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2926:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2952:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor2962:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor3220:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigor3912:-:*:*:*:*:*:*:*
cpe:2.3:h:draytek:vigorlte200:-:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor1000b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor165_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor166_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2133_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2135_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2620_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2762_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2763_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2765_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2766_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2832_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2860_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2862_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2865_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2866_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2915_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2925_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2926_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2952_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor2962_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor3220_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigor3912_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:draytek:vigorlte200_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek vigor1000b
Draytek vigor1000b Firmware
Draytek vigor165
Draytek vigor165 Firmware
Draytek vigor166
Draytek vigor166 Firmware
Draytek vigor2133
Draytek vigor2133 Firmware
Draytek vigor2135
Draytek vigor2135 Firmware
Draytek vigor2620
Draytek vigor2620 Firmware
Draytek vigor2762
Draytek vigor2762 Firmware
Draytek vigor2763
Draytek vigor2763 Firmware
Draytek vigor2765
Draytek vigor2765 Firmware
Draytek vigor2766
Draytek vigor2766 Firmware
Draytek vigor2832
Draytek vigor2832 Firmware
Draytek vigor2860
Draytek vigor2860 Firmware
Draytek vigor2862
Draytek vigor2862 Firmware
Draytek vigor2865
Draytek vigor2865 Firmware
Draytek vigor2866
Draytek vigor2866 Firmware
Draytek vigor2915
Draytek vigor2915 Firmware
Draytek vigor2925
Draytek vigor2925 Firmware
Draytek vigor2926
Draytek vigor2926 Firmware
Draytek vigor2952
Draytek vigor2952 Firmware
Draytek vigor2962
Draytek vigor2962 Firmware
Draytek vigor3220
Draytek vigor3220 Firmware
Draytek vigor3912
Draytek vigor3912 Firmware
Draytek vigorlte200
Draytek vigorlte200 Firmware

Thu, 10 Apr 2025 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Draytek vigor3910
CPEs cpe:2.3:h:draytek:vigor3910:-:*:*:*:*:*:*:*
Vendors & Products Draytek vigor3910

Thu, 03 Oct 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Draytek
Draytek vigor3910 Firmware
Weaknesses CWE-121
CPEs cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:*
Vendors & Products Draytek
Draytek vigor3910 Firmware
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Oct 2024 18:45:00 +0000

Type Values Removed Values Added
Description DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.
References

Subscriptions

Draytek Vigor1000b Vigor1000b Firmware Vigor165 Vigor165 Firmware Vigor166 Vigor166 Firmware Vigor2133 Vigor2133 Firmware Vigor2135 Vigor2135 Firmware Vigor2620 Vigor2620 Firmware Vigor2762 Vigor2762 Firmware Vigor2763 Vigor2763 Firmware Vigor2765 Vigor2765 Firmware Vigor2766 Vigor2766 Firmware Vigor2832 Vigor2832 Firmware Vigor2860 Vigor2860 Firmware Vigor2862 Vigor2862 Firmware Vigor2865 Vigor2865 Firmware Vigor2866 Vigor2866 Firmware Vigor2915 Vigor2915 Firmware Vigor2925 Vigor2925 Firmware Vigor2926 Vigor2926 Firmware Vigor2952 Vigor2952 Firmware Vigor2962 Vigor2962 Firmware Vigor3220 Vigor3220 Firmware Vigor3910 Vigor3910 Firmware Vigor3912 Vigor3912 Firmware Vigorlte200 Vigorlte200 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-10-03T18:59:51.817Z

Reserved: 2024-07-18T00:00:00.000Z

Link: CVE-2024-41592

cve-icon Vulnrichment

Updated: 2024-10-03T18:58:05.336Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-03T19:15:04.633

Modified: 2025-06-03T13:52:04.560

Link: CVE-2024-41592

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses