10

CVE-2022-32548

Exploit
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraytekVigor3910 Firmware Version < 4.3.1.1
   DraytekVigor3910 Version-
DraytekVigor1000b Firmware Version < 4.3.1.1
   DraytekVigor1000b Version-
DraytekVigor2962 Firmware Version < 4.3.1.1
   DraytekVigor2962 Version-
DraytekVigor2962p Firmware Version < 4.3.1.1
   DraytekVigor2962p Version-
DraytekVigor2927 Firmware Version < 4.4.0
   DraytekVigor2927 Version-
DraytekVigor2927ax Firmware Version < 4.4.0
   DraytekVigor2927ax Version-
DraytekVigor2927ac Firmware Version < 4.4.0
   DraytekVigor2927ac Version-
DraytekVigor2927vac Firmware Version < 4.4.0
   DraytekVigor2927vac Version-
DraytekVigor2927l Firmware Version < 4.4.0
   DraytekVigor2927l Version-
DraytekVigor2927lac Firmware Version < 4.4.0
   DraytekVigor2927lac Version-
DraytekVigor2915 Firmware Version < 4.3.3.2
   DraytekVigor2915 Version-
DraytekVigor2915ac Firmware Version < 4.3.3.2
   DraytekVigor2915ac Version-
DraytekVigor2952 Firmware Version < 3.9.7.2
   DraytekVigor2952 Version-
DraytekVigor2952p Firmware Version < 3.9.7.2
   DraytekVigor2952p Version-
DraytekVigor3220 Firmware Version < 3.9.7.2
   DraytekVigor3220 Version-
DraytekVigor2926 Firmware Version < 3.9.8.1
   DraytekVigor2926 Version-
DraytekVigor2926n Firmware Version < 3.9.8.1
   DraytekVigor2926n Version-
DraytekVigor2926ac Firmware Version < 3.9.8.1
   DraytekVigor2926ac Version-
DraytekVigor2926vac Firmware Version < 3.9.8.1
   DraytekVigor2926vac Version-
DraytekVigor2926l Firmware Version < 3.9.8.1
   DraytekVigor2926l Version-
DraytekVigor2926ln Firmware Version < 3.9.8.1
   DraytekVigor2926ln Version-
DraytekVigor2926lac Firmware Version < 3.9.8.1
   DraytekVigor2926lac Version-
DraytekVigor2862 Firmware Version < 3.9.8.1
   DraytekVigor2862 Version-
DraytekVigor2862n Firmware Version < 3.9.8.1
   DraytekVigor2862n Version-
DraytekVigor2862ac Firmware Version < 3.9.8.1
   DraytekVigor2862ac Version-
DraytekVigor2862vac Firmware Version < 3.9.8.1
   DraytekVigor2862vac Version-
DraytekVigor2862b Firmware Version < 3.9.8.1
   DraytekVigor2862b Version-
DraytekVigor2862bn Firmware Version < 3.9.8.1
   DraytekVigor2862bn Version-
DraytekVigor2862l Firmware Version < 3.9.8.1
   DraytekVigor2862l Version-
DraytekVigor2862ln Firmware Version < 3.9.8.1
   DraytekVigor2862ln Version-
DraytekVigor2862lac Firmware Version < 3.9.8.1
   DraytekVigor2862lac Version-
DraytekVigor2620l Firmware Version < 3.9.8.1
   DraytekVigor2620l Version-
DraytekVigor2620ln Firmware Version < 3.9.8.1
   DraytekVigor2620ln Version-
DraytekVigorlte 200n Firmware Version < 3.9.8.1
   DraytekVigorlte 200n Version-
DraytekVigor2133 Firmware Version < 3.9.6.4
   DraytekVigor2133 Version-
DraytekVigor2133n Firmware Version < 3.9.6.4
   DraytekVigor2133n Version-
DraytekVigor2133ac Firmware Version < 3.9.6.4
   DraytekVigor2133ac Version-
DraytekVigor2133vac Firmware Version < 3.9.6.4
   DraytekVigor2133vac Version-
DraytekVigor2133fvac Firmware Version < 3.9.6.4
   DraytekVigor2133fvac Version-
DraytekVigor2762 Firmware Version < 3.9.6.4
   DraytekVigor2762 Version-
DraytekVigor2762n Firmware Version < 3.9.6.4
   DraytekVigor2762n Version-
DraytekVigor2762ac Firmware Version < 3.9.6.4
   DraytekVigor2762ac Version-
DraytekVigor2762vac Firmware Version < 3.9.6.4
   DraytekVigor2762vac Version-
DraytekVigor165 Firmware Version < 4.2.4
   DraytekVigor165 Version-
DraytekVigor166 Firmware Version < 4.2.4
   DraytekVigor166 Version-
DraytekVigor2135 Firmware Version < 4.4.2
   DraytekVigor2135 Version-
DraytekVigor2135ac Firmware Version < 4.4.2
   DraytekVigor2135ac Version-
DraytekVigor2135vac Firmware Version < 4.4.2
   DraytekVigor2135vac Version-
DraytekVigor2135fvac Firmware Version < 4.4.2
   DraytekVigor2135fvac Version-
DraytekVigor2765 Firmware Version < 4.4.2
   DraytekVigor2765 Version-
DraytekVigor2765ac Firmware Version < 4.4.2
   DraytekVigor2765ac Version-
DraytekVigor2765vac Firmware Version < 4.4.2
   DraytekVigor2765vac Version-
DraytekVigor2766 Firmware Version < 4.4.2
   DraytekVigor2766 Version-
DraytekVigor2766ac Firmware Version < 4.4.2
   DraytekVigor2766ac Version-
DraytekVigor2766vac Firmware Version < 4.4.2
   DraytekVigor2766vac Version-
DraytekVigor2832 Firmware Version < 3.9.6
   DraytekVigor2832 Version-
DraytekVigor2865 Firmware Version < 4.4.0
   DraytekVigor2865 Version-
DraytekVigor2865ax Firmware Version < 4.4.0
   DraytekVigor2865ax Version-
DraytekVigor2865ac Firmware Version < 4.4.0
   DraytekVigor2865ac Version-
DraytekVigor2865vac Firmware Version < 4.4.0
   DraytekVigor2865vac Version-
DraytekVigor2865l Firmware Version < 4.4.0
   DraytekVigor2865l Version-
DraytekVigor2865lac Firmware Version < 4.4.0
   DraytekVigor2865lac Version-
DraytekVigor2866 Firmware Version < 4.4.0
   DraytekVigor2866 Version-
DraytekVigor2866ax Firmware Version < 4.4.0
   DraytekVigor2866ax Version-
DraytekVigor2866ac Firmware Version < 4.4.0
   DraytekVigor2866ac Version-
DraytekVigor2866vac Firmware Version < 4.4.0
   DraytekVigor2866vac Version-
DraytekVigor2866l Firmware Version < 4.4.0
   DraytekVigor2866l Version-
DraytekVigor2866lac Firmware Version < 4.4.0
   DraytekVigor2866lac Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 70.53% 0.987
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
cve@mitre.org 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.