VYPR

Vigor3910 Firmware

by Draytek

CVEs (60)

  • CVE-2024-46564HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at fextobj.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46561HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the queryret parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46560HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pub_key parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46559HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_UsrNme parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46558HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the newProname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46557HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sProfileName parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46556HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sInRCSecret0 parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46555HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the pb parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46554HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the profname parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46553HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ipaddrmsk%d parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46552HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sStRtMskShow parameter at ipstrt.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46551HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sBPA_Pwd parameter at inet15.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-46550HigSep 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the CGIbyFieldName parameter at chglog.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

  • CVE-2024-23721HigMar 20, 2024
    risk 0.49cvss 7.5epss 0.01

    A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports information.

  • CVE-2024-41585MedOct 3, 2024
    risk 0.44cvss 6.8epss 0.01

    DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.

  • CVE-2024-41591MedOct 3, 2024
    risk 0.40cvss 6.1epss 0.00

    DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

  • CVE-2023-23313MedMar 3, 2023
    risk 0.40cvss 6.1epss 0.00

    Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi script of the router's web application management portal. This affects Vigor3910, Vigor1000B, Vigor2962 v4.3.2.1; Vigor2865 and Vigor2866 v4.4.1.0; Vigor2927…

  • CVE-2024-41587MedOct 3, 2024
    risk 0.35cvss 5.4epss 0.00

    Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.

  • CVE-2024-41584MedOct 3, 2024
    risk 0.31cvss 4.7epss 0.00

    DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.

  • CVE-2024-41583MedOct 3, 2024
    risk 0.31cvss 4.7epss 0.00

    DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.

Page 3 of 3