Перейти к содержимому
Noroxi

Записи DrayTek

134 опубликованных записей вендора draytek.

Профиль для исследователя

Попали в KEV
5 · 3,7 %
С эксплойтом
5 · 3,7 %
Pre-auth RCE
22
С записью об исправлении
1,5 %
Медиана: публикация → KEV
1056 дн.

Все записи

134 записей
  • CVE-2020-8515
    99Срочно

    DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    draytek · vigor2960 firmware1 февр. 2020 г.

  • CVE-2020-15415
    94Срочно

    On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution v

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %

    draytek · vigor3900 firmware30 июн. 2020 г.

  • CVE-2021-20124
    89Срочно

    A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the WebServlet endpoint.

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 96 %

    draytek · vigorconnect13 окт. 2021 г.

  • CVE-2021-20123
    87Срочно

    A local file inclusion vulnerability exists in Draytek VigorConnect 1.6.0-B3 in the file download functionality of the DownloadFileServlet e

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 90 %

    draytek · vigorconnect13 окт. 2021 г.

  • CVE-2024-12987
    86Срочно

    DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

    СредняяCVSS 6,9KEVГотовый эксплойтEPSS 98 %

    draytek · vigor300b firmware27 дек. 2024 г.

  • CVE-2020-10826
    51В плане

    /cgi-bin/activate.cgi on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve command injecti

    КритическаяCVSS 9,8Эксплойта нетEPSS 39 %

    draytek · vigor300b firmware26 мар. 2020 г.

  • CVE-2021-43118
    49В плане

    A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 vi

    КритическаяCVSS 9,8Эксплойта нетEPSS 35 %

    draytek · vigor2960 firmware29 мар. 2022 г.

  • CVE-2022-32548
    49В плане

    An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1.

    КритическаяCVSS 9,8Proof of conceptEPSS 34 %

    draytek · vigor3910 firmware29 авг. 2022 г.

  • CVE-2020-10828
    45В плане

    A stack-based buffer overflow in cvmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve

    КритическаяCVSS 9,8Эксплойта нетEPSS 21 %

    draytek · vigor300b firmware26 мар. 2020 г.

  • CVE-2020-10827
    45В плане

    A stack-based buffer overflow in apmd on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1 allows remote attackers to achieve

    КритическаяCVSS 9,8Эксплойта нетEPSS 21 %

    draytek · vigor300b firmware26 мар. 2020 г.

  • CVE-2023-1162
    43В плане

    DrayTek Vigor 2960 Web Management Interface mainfunction.cgi command injection

    ВысокаяCVSS 8,8Эксплойта нетEPSS 26 %

    draytek · vigor 2960 firmware3 мар. 2023 г.

  • CVE-2020-14993
    41В плане

    A stack-based buffer overflow on DrayTek Vigor2960, Vigor3900, and Vigor300B devices before 1.5.1.1 allows remote attackers to execute arbit

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    draytek · vigor300b firmware23 июн. 2020 г.

  • CVE-2020-10823
    40В плане

    A stack-based buffer overflow in /cgi-bin/activate.cgi through var parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices before 1

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    draytek · vigor300b firmware26 мар. 2020 г.

  • CVE-2020-10824
    40В плане

    A stack-based buffer overflow in /cgi-bin/activate.cgi through ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B devices befor

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    draytek · vigor300b firmware26 мар. 2020 г.

  • CVE-2020-10825
    40В плане

    A stack-based buffer overflow in /cgi-bin/activate.cgi while base64 decoding ticket parameter on Draytek Vigor3900, Vigor2960, and Vigor300B

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    draytek · vigor300b firmware26 мар. 2020 г.

  • CVE-2021-20125
    40В плане

    An arbitrary file upload and directory traversal vulnerability exists in the file upload functionality of DownloadFileServlet in Draytek Vig

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    draytek · vigorconnect13 окт. 2021 г.

  • CVE-2021-42911
    40В плане

    A Format String vulnerability exists in DrayTek Vigor 2960 <= 1.5.1.3, DrayTek Vigor 3900 <= 1.5.1.3, and DrayTek Vigor 300B <= 1.5.1.3 in t

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    draytek · vigor2960 firmware29 мар. 2022 г.

  • CVE-2020-14472
    40В плане

    On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    draytek · vigor300b firmware24 июн. 2020 г.

  • CVE-2020-14473
    40В плане

    Stack-based buffer overflow vulnerability in Vigor3900, Vigor2960, and Vigor300B with firmware before 1.5.1.1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    draytek · vigor300b firmware24 июн. 2020 г.

  • CVE-2023-47254
    40В плане

    An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    draytek · vigor167 firmware9 дек. 2023 г.

  • CVE-2024-51138
    39Наблюдать

    Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier;

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    draytek · vigor3912 firmware27 февр. 2025 г.

  • CVE-2024-51139
    39Наблюдать

    Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and ea

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    draytek · vigor2620 firmware27 февр. 2025 г.

  • CVE-2023-31447
    39Наблюдать

    user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted pay

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    draytek · vigor2620 firmware21 авг. 2023 г.

  • CVE-2024-41593
    39Наблюдать

    DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    draytek · vigor3912 firmware3 окт. 2024 г.

  • CVE-2024-51252
    39Наблюдать

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the re

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    draytek · vigor3900 firmware1 нояб. 2024 г.