8.8
CVE-2024-41339
- EPSS 0.3%
- Veröffentlicht 27.02.2025 21:15:36
- Zuletzt bearbeitet 03.06.2025 13:52:39
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload a crafted kernel module, allowing for arbitrary code execution.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Draytek ≫ Vigor165 Firmware Version < 4.2.7
Draytek ≫ Vigor166 Firmware Version < 4.2.7
Draytek ≫ Vigor2620 Firmware Version < 3.9.8.9
Draytek ≫ Vigorlte200 Firmware Version < 3.9.8.9
Draytek ≫ Vigor2860 Firmware Version < 3.9.8
Draytek ≫ Vigor2925 Firmware Version < 3.9.8
Draytek ≫ Vigor2862 Firmware Version < 3.9.9.5
Draytek ≫ Vigor2926 Firmware Version < 3.9.9.5
Draytek ≫ Vigor2133 Firmware Version < 3.9.9
Draytek ≫ Vigor2762 Firmware Version < 3.9.9
Draytek ≫ Vigor2832 Firmware Version < 3.9.9
Draytek ≫ Vigor2135 Firmware Version < 4.4.5.1
Draytek ≫ Vigor2765 Firmware Version < 4.4.5.1
Draytek ≫ Vigor2766 Firmware Version < 4.4.5.1
Draytek ≫ Vigor2865 Firmware Version < 4.4.5.3
Draytek ≫ Vigor2866 Firmware Version < 4.4.5.3
Draytek ≫ Vigor2927 Firmware Version < 4.4.5.3
Draytek ≫ Vigor2962 Firmware Version < 4.3.2.8
Draytek ≫ Vigor2962 Firmware Version4.4.3.0
Draytek ≫ Vigor3910 Firmware Version < 4.3.2.8
Draytek ≫ Vigor3910 Firmware Version4.4.3
Draytek ≫ Vigor3912 Firmware Version < 4.3.6.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.3% | 0.53 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.