Critical severity10.0NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026
CVE-2022-32548
CVE-2022-32548
Description
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
71- cpe:2.3:o:draytek:vigor2133fvac_firmware:*:*:*:*:*:*:*:*Range: <3.9.6.4
- cpe:2.3:o:draytek:vigorlte_200n_firmware:*:*:*:*:*:*:*:*Range: <3.9.8.1
Patches
Vulnerability mechanics
References
2- www.securityweek.com/smbs-exposed-attacks-critical-vulnerability-draytek-vigor-routersnvdExploitThird Party Advisory
- www.trellix.com/en-us/about/newsroom/stories/threat-labs/rce-in-dratyek-routers.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.