PT-2024-7429 · Draytek · Draytek Vigor310

Published

2024-10-02

·

Updated

2025-04-10

·

CVE-2024-41586

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DrayTek Vigor310 versions through 4.3.2.6
Description: The issue is related to a stack-based Buffer Overflow vulnerability in the /cgi-bin/ipfedr.cgi component of the DrayTek Vigor310 devices' web interface. This vulnerability can be exploited by a remote attacker, allowing them to execute arbitrary code or cause a denial of service by sending a specially crafted HTTP request with a long query string.
Recommendations: For DrayTek Vigor310 versions through 4.3.2.6, consider disabling access to the /cgi-bin/ipfedr.cgi component until a patch is available. Restricting access to this component can help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-08807
CVE-2024-41586

Affected Products

Draytek Vigor310