8.4

CVE-2024-41340

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraytekVigor165 Firmware Version < 4.2.7
   DraytekVigor165 Version-
DraytekVigor166 Firmware Version < 4.2.7
   DraytekVigor166 Version-
DraytekVigor2620 Firmware Version < 3.9.8.9
   DraytekVigor2620 Version-
DraytekVigorlte200 Firmware Version < 3.9.8.9
   DraytekVigorlte200 Version-
DraytekVigor2860 Firmware Version < 3.9.8
   DraytekVigor2860 Version-
DraytekVigor2925 Firmware Version < 3.9.8
   DraytekVigor2925 Version-
DraytekVigor2862 Firmware Version < 3.9.9.5
   DraytekVigor2862 Version-
DraytekVigor2926 Firmware Version < 3.9.9.5
   DraytekVigor2926 Version-
DraytekVigor2133 Firmware Version < 3.9.9
   DraytekVigor2133 Version-
DraytekVigor2762 Firmware Version < 3.9.9
   DraytekVigor2762 Version-
DraytekVigor2832 Firmware Version < 3.9.9
   DraytekVigor2832 Version-
DraytekVigor2135 Firmware Version < 4.4.5.1
   DraytekVigor2135 Version-
DraytekVigor2765 Firmware Version < 4.4.5.1
   DraytekVigor2765 Version-
DraytekVigor2766 Firmware Version < 4.4.5.1
   DraytekVigor2766 Version-
DraytekVigor2865 Firmware Version < 4.4.5.3
   DraytekVigor2865 Version-
DraytekVigor2866 Firmware Version < 4.4.5.3
   DraytekVigor2866 Version-
DraytekVigor2927 Firmware Version < 4.4.5.3
   DraytekVigor2927 Version-
DraytekVigor2962 Firmware Version < 4.3.2.8
   DraytekVigor2962 Version-
DraytekVigor2962 Firmware Version4.4.3.0
   DraytekVigor2962 Version-
DraytekVigor3910 Firmware Version < 4.3.2.8
   DraytekVigor3910 Version-
DraytekVigor3910 Firmware Version4.4.3
   DraytekVigor3910 Version-
DraytekVigor3912 Firmware Version < 4.3.6.1
   DraytekVigor3912 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.113
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.