Vulnerabilities
133 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-3040 | A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor confirms that "300B is EoL, and this is an authenticated vulnerability. We don't plan to fix it." This vulnerability only affects products that are no longer supported by the maintainer. NVD description · AI analysis pending | 2.0 | 9% | PoC |
| — | |
| CVE-2024-51139 | Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/ Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the "Content-Length" header of HTTP POST requests. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-51138 | Vigor165/166 4.2.7 and earlier; Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 4.4.5.3 and earlier; Vigor2962 4.3.2.8 and earlier; Vigor3912 4.3.6.1 and earlier; Vigor3910 4.4.3.1 and earlier a stack-based buffer overflow vulnerability has been identified in the URL parsing functionality of the TR069 STUN server. This flaw occurs due to insufficient bounds checking on the amount of URL parameters, allowing an attacker to exploit the overflow by sending a maliciously crafted request. Consequently, a remote attacker can execute arbitrary code with elevated privileges. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2024-41339 | An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/29 An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload a crafted kernel module, allowing for arbitrary code execution. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-41334 | Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2 Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-12987 | OS Command Injection in DrayTek Vigor2960/300B Web Interface CVE-2024-12987 is an OS command injection flaw in the web management interface of DrayTek Vigor2960 and Vigor300B routers running firmware 1.5.1.4. An unauthenticated remote attacker triggers it by sending a crafted request to the /cgi-bin/mainfunction.cgi/apmcfgupload endpoint with a manipulated 'session' parameter, which is passed to the underlying operating system without proper sanitization (CWE-77/CWE-78). Successful exploitation yields arbitrary operating-system command execution on the router, which can mean full device compromise and a foothold for pivoting into the protected network. Any organization running affected firmware on these models is exposed, especially sites where the management interface is reachable from the internet. Exploitation is confirmed in the wild: a public proof-of-concept is available, EPSS assigns a 98.1% probability of exploitation within 30 days (100th percentile), and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-05-15, requiring federal remediation under BOD 22-01. Do: Upgrade Vigor2960 and Vigor300B units from firmware 1.5.1.4 to version 1.5.1.5 or later. Until patched, restrict internet-facing access to the web management interface and review device logs for suspicious requests to /cgi-bin/mainfunction.cgi/apmcfgupload containing anomalous session parameters. Because the flaw is in CISA's KEV catalog, federal agencies must apply the vendor fix or applicable BOD 22-01 mitigations by the required deadline. | 6.9 | 98% | KEV PoC |
| largeplausibly tens of thousands of internet-exposed devices | |
| CVE-2024-12986 | Unauthenticated OS Command Injection in DrayTek Vigor2960/300B Web Interface CVE-2024-12986 is an OS command injection flaw in the web management interface of DrayTek Vigor2960 and Vigor300B gateways running firmware 1.5.1.3 or 1.5.1.4. It is triggered by sending a crafted, unauthenticated HTTP request to the /cgi-bin/mainfunction.cgi/apmcfgupptim endpoint with a manipulated 'session' argument, which is passed into an OS command. A remote attacker with no privileges or user interaction gains the ability to execute arbitrary operating-system commands on the affected device. Any organization running these two DrayTek models on the affected firmware is exposed, particularly where the web management interface is reachable from untrusted networks. A public proof-of-concept has been disclosed, EPSS assigns a 32.8% probability of exploitation within 30 days (98th percentile), the flaw is not yet in CISA KEV, and there is no confirmed in-the-wild exploitation. Do: Upgrade Vigor2960 and Vigor300B firmware to version 1.5.1.5 or later. Until patched, restrict access to the web management interface (allow it only from trusted management networks and avoid WAN exposure), and check device firmware versions plus logs for unexpected requests to /cgi-bin/mainfunction.cgi/apmcfgupptim. | 6.9 | 33% | PoC |
| large≈ tens of thousands of internet-exposed gateways | |
| CVE-2024-45890 | DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainf DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.` NVD description · AI analysis pending | 8.0 | 2% |
| — | ||
| CVE-2024-51252 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function. In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function. NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2024-51260 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process functio DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-51298 | In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function. In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function. NVD description · AI analysis pending | 9.8 group max | <1% |
| — | ||
| CVE-2024-48074 | An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter o An authorized RCE vulnerability exists in the DrayTek Vigor2960 router version 1.4.4, where an attacker can place a malicious command into the table parameter of the doPPPoE function in the cgi-bin/mainfunction.cgi route, and finally the command is executed by the system function. NVD description · AI analysis pending | 8.0 | <1% | PoC |
| — | |
| CVE-2024-48153 | DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig functi DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-46316 | DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. DrayTek Vigor3900 v1.5.1.6 was discovered to contain a command injection vulnerability via the sub_2C920 function at /cgi-bin/mainfunction.cgi. This vulnerability allows attackers to execute arbitrary commands via supplying a crafted HTTP message. NVD description · AI analysis pending | 8.0 | 1% |
| — | ||
| CVE-2024-41596 | Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters. NVD description · AI analysis pending | 8.0 group max | <1% |
| — | ||
| CVE-2024-41589 +1 in the same advisory: …41595 | DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-41593 | DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension oper DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2024-41592 | DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand cha DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs. NVD description · AI analysis pending | 8.0 | 1% | PoC |
| — | |
| CVE-2024-41590 | Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6. NVD description · AI analysis pending | 8.0 | <1% |
| — |