📦 Vigor3910 Firmware

by Draytek

🔍 What is Vigor3910 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-51138

CRITICAL CVSS 9.8 Feb 27, 2025

A critical stack-based buffer overflow vulnerability in DrayTek router TR069 STUN server URL parsing allows remote attackers to execute arbitrary code with elevated privileges. This affects multiple D...

CVE-2024-41593

CRITICAL CVSS 9.8 Oct 3, 2024

CVE-2024-41593 is a critical heap-based buffer overflow vulnerability in DrayTek Vigor310 devices that allows remote attackers to execute arbitrary code. The vulnerability occurs due to sign-extension...

CVE-2023-33778

CRITICAL CVSS 9.8 Jun 1, 2023

Draytek Vigor routers, access points, switches, and Myvigor firmware use hardcoded encryption keys, allowing attackers to bind affected devices to their own accounts. This enables unauthorized creatio...

CVE-2024-41338

HIGH CVSS 7.5 Feb 27, 2025

A NULL pointer dereference vulnerability in multiple Draytek router models allows attackers to cause Denial of Service (DoS) via specially crafted DHCP requests. This affects organizations and individ...

CVE-2024-41339

HIGH CVSS 8.8 Feb 27, 2025

This vulnerability allows attackers to upload malicious kernel modules through the CGI configuration upload endpoint in affected Draytek routers, leading to arbitrary code execution with root privileg...

CVE-2024-41340

HIGH CVSS 8.4 Feb 27, 2025

This vulnerability in Draytek routers allows attackers to upload malicious APP Enforcement modules, leading to arbitrary code execution with root privileges. It affects multiple Draytek Vigor router m...

CVE-2024-41586

HIGH CVSS 8.0 Oct 3, 2024

A stack-based buffer overflow vulnerability in DrayTek Vigor310 devices allows remote attackers to execute arbitrary code by sending a specially crafted long query string to the cgi-bin/ipfedr.cgi com...

CVE-2024-41588

HIGH CVSS 8.0 Oct 3, 2024

This vulnerability allows authenticated users to exploit buffer overflows in DrayTek Vigor3910 devices by sending specially crafted POST requests to vulnerable CGI endpoints. Attackers could potential...

CVE-2024-41590

HIGH CVSS 8.0 Oct 3, 2024

This vulnerability allows authenticated users to exploit buffer overflows in CGI endpoints on DrayTek Vigor310 devices by sending specially crafted POST requests. Attackers could potentially execute a...

CVE-2024-41592

HIGH CVSS 8.0 Oct 3, 2024

DrayTek Vigor3910 devices have a stack-based buffer overflow vulnerability in the GetCGI function that processes query string parameters. Attackers can exploit this by sending specially crafted HTTP r...

CVE-2024-41595

HIGH CVSS 8.0 Oct 3, 2024

DrayTek Vigor310 devices through firmware version 4.3.2.6 contain buffer overflow vulnerabilities in .cgi pages due to missing bounds checks. This allows remote attackers to change device settings or ...

CVE-2024-46589

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sIpv6AiccuUser parameter. This affects organizations usi...

CVE-2024-46591

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to the sDnsPro parameter. This affects organizations ...

CVE-2024-46593

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the trapcomm parameter in cgiswm.cgi. This affects organizat...

CVE-2024-46595

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the saveitem parameter in lan2lan.cgi. This affects organiza...

CVE-2024-46597

HIGH CVSS 7.5 Sep 18, 2024

CVE-2024-46597 is a buffer overflow vulnerability in Draytek Vigor 3910 routers affecting the sPubKey parameter in dialin.cgi. Attackers can exploit this by sending crafted inputs to cause Denial of S...

CVE-2024-46558

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the newProname parameter in v2x00.cgi. This affects organiza...

CVE-2024-46560

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to the pub_key parameter. This affects organizations ...

CVE-2024-46564

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sProfileName parameter in fextobj.cgi. This affects orga...

CVE-2024-46566

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability exists in the sAppName parameter of the sslapp.cgi component in Draytek Vigor 3910 firmware v4.3.2.6. Attackers can exploit this by sending crafted inputs to cause a De...

CVE-2024-46568

HIGH CVSS 7.5 Sep 18, 2024

This vulnerability allows attackers to cause a Denial of Service (DoS) on Draytek Vigor 3910 routers by exploiting a buffer overflow in the sPeerId parameter of the vpn.cgi component. Attackers can cr...

CVE-2024-46580

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in the Draytek Vigor 3910 router's v2x00.cgi component allows attackers to cause Denial of Service (DoS) by sending specially crafted input to the fid parameter. This a...

CVE-2024-46582

HIGH CVSS 7.5 Sep 18, 2024

This vulnerability allows attackers to trigger a buffer overflow in Draytek Vigor 3910 routers by sending crafted input to the sSrvAddr parameter in v2x00.cgi. This causes a Denial of Service (DoS), p...

CVE-2024-46584

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability exists in the AControlIp1 parameter of the acontrol.cgi component in Draytek Vigor 3910 firmware version 4.3.2.6. Attackers can exploit this by sending specially crafte...

CVE-2024-46586

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending specially crafted input to the sCloudPass parameter. This affects organizatio...

CVE-2024-46550

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the CGIbyFieldName parameter in chglog.cgi. This affects org...

CVE-2024-46552

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sStRtMskShow parameter. This affects organizations using...

CVE-2024-46554

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability exists in the profname parameter of the v2x00.cgi component in Draytek Vigor 3910 firmware version 4.3.2.6. Attackers can exploit this by sending specially crafted inpu...

CVE-2024-46556

HIGH CVSS 7.5 Sep 18, 2024

A buffer overflow vulnerability in Draytek Vigor 3910 routers allows attackers to cause Denial of Service (DoS) by sending crafted input to the sInRCSecret0 parameter. This affects organizations using...

CVE-2024-23721

HIGH CVSS 7.5 Mar 20, 2024

CVE-2024-23721 is a directory traversal vulnerability in Draytek Vigor3910 devices that allows attackers to access sensitive system files by manipulating POST requests. This affects organizations usin...

CVE-2024-41584

MEDIUM CVSS 4.7 Oct 3, 2024

This vulnerability allows authenticated attackers to inject malicious scripts via the sFormAuthStr parameter, which are then executed in victims' browsers when they view the affected page. It affects ...