Vigor166 Firmware

Draytek · 15 CVEs

CVE-2024-41340
HIGH

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior…

Feb 27, 2025

CVE-2024-41339
HIGH

An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 262…

Feb 27, 2025

CVE-2024-41338
HIGH

A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigo…

Feb 27, 2025

CVE-2024-41334
HIGH

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, V…

Feb 27, 2025

CVE-2024-41596
HIGH

Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because…

Oct 3, 2024

CVE-2024-41594
HIGH

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the htt…

Oct 3, 2024

CVE-2024-41593
CRITICAL

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_…

Oct 3, 2024

CVE-2024-41592
HIGH

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because G…

Oct 3, 2024

CVE-2024-41591
MEDIUM

DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.

Oct 3, 2024

CVE-2024-41590
HIGH

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on…

Oct 3, 2024

CVE-2024-41588
HIGH

The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overfl…

Oct 3, 2024

CVE-2024-41587
MEDIUM

Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor3…

Oct 3, 2024

CVE-2023-33778
CRITICAL

Draytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmw…

Jun 1, 2023

CVE-2023-23313
MEDIUM

Certain Draytek products are vulnerable to Cross Site Scripting (XSS) via the wlogin.cgi script and user_login.cgi scri…

Mar 3, 2023

CVE-2022-32548
CRITICAL

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bi…

Aug 29, 2022

Showing 1 to 15 of 15 CVEs