9.8

CVE-2024-51139

Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the "Content-Length" header of HTTP POST requests.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DraytekVigor2620 Firmware Version < 3.9.9.1
   DraytekVigor2620 Version-
DraytekVigorlte200 Firmware Version < 3.9.9.1
   DraytekVigorlte200 Version-
DraytekVigor2860 Firmware Version < 3.9.8.3
   DraytekVigor2860 Version-
DraytekVigor2925 Firmware Version < 3.9.8.3
   DraytekVigor2925 Version-
DraytekVigor2862 Firmware Version < 3.9.9.8
   DraytekVigor2862 Version-
DraytekVigor2926 Firmware Version < 3.9.9.8
   DraytekVigor2926 Version-
DraytekVigor2133 Firmware Version < 3.9.9.2
   DraytekVigor2133 Version-
DraytekVigor2762 Firmware Version < 3.9.9.2
   DraytekVigor2762 Version-
DraytekVigor2832 Firmware Version < 3.9.9.2
   DraytekVigor2832 Version-
DraytekVigor2135 Firmware Version < 4.4.5.5
   DraytekVigor2135 Version-
DraytekVigor2765 Firmware Version < 4.4.5.5
   DraytekVigor2765 Version-
DraytekVigor2766 Firmware Version < 4.4.5.5
   DraytekVigor2766 Version-
DraytekVigor2763 Firmware Version < 4.4.5.5
   DraytekVigor2763 Version-
DraytekVigor2865 Firmware Version < 4.4.5.8
   DraytekVigor2865 Version-
DraytekVigor2866 Firmware Version < 4.4.5.8
   DraytekVigor2866 Version-
DraytekVigor2927 Firmware Version < 4.4.5.8
   DraytekVigor2927 Version-
DraytekVigor2962 Firmware Version < 4.3.2.9
   DraytekVigor2962 Version-
DraytekVigor2962 Firmware Version >= 4.4.3 < 4.4.3.2
   DraytekVigor2962 Version-
DraytekVigor3910 Firmware Version < 4.3.2.9
   DraytekVigor3910 Version-
DraytekVigor3910 Firmware Version >= 4.4.3 < 4.4.3.2
   DraytekVigor3910 Version-
DraytekVigor3912 Firmware Version < 4.4.3.2
   DraytekVigor3912 Version-
DraytekVigor2915 Firmware Version < 4.4.5
   DraytekVigor2915 Version-
DraytekVigor1000b Firmware Version < 4.4.3.2
   DraytekVigor1000b Version-
DraytekVigor2952 Firmware Version < 3.9.8.5
   DraytekVigor2952 Version-
DraytekVigor3220 Firmware Version < 3.9.8.5
   DraytekVigor3220 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.721
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.