CVE-2024-41338
A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to cause a Denial of Service (DoS) via a crafted DHCP request.
Published:Feb 27, 2025
Last Modified:Jun 3, 2025
EPS:Feb 27, 2025
EPSS Score:0.00103
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Draytek
Product
Vigor165
Draytek
Vigor165
Vendor
Draytek
Product
Vigor165 Firmware
Draytek
Vigor165 Firmware
Vendor
Draytek
Product
Vigor166
Draytek
Vigor166
Vendor
Draytek
Product
Vigor166 Firmware
Draytek
Vigor166 Firmware
Vendor
Draytek
Product
Vigor2133
Draytek
Vigor2133
Vendor
Draytek
Product
Vigor2133 Firmware
Draytek
Vigor2133 Firmware
Vendor
Draytek
Product
Vigor2135
Draytek
Vigor2135
Vendor
Draytek
Product
Vigor2135 Firmware
Draytek
Vigor2135 Firmware
Vendor
Draytek
Product
Vigor2620
Draytek
Vigor2620
Vendor
Draytek
Product
Vigor2620 Firmware
Draytek
Vigor2620 Firmware
Vendor
Draytek
Product
Vigor2762
Draytek
Vigor2762
Vendor
Draytek
Product
Vigor2762 Firmware
Draytek
Vigor2762 Firmware
Vendor
Draytek
Product
Vigor2765
Draytek
Vigor2765
Vendor
Draytek
Product
Vigor2765 Firmware
Draytek
Vigor2765 Firmware
Vendor
Draytek
Product
Vigor2766
Draytek
Vigor2766
Vendor
Draytek
Product
Vigor2766 Firmware
Draytek
Vigor2766 Firmware
Vendor
Draytek
Product
Vigor2832
Draytek
Vigor2832
Vendor
Draytek
Product
Vigor2832 Firmware
Draytek
Vigor2832 Firmware
Vendor
Draytek
Product
Vigor2860
Draytek
Vigor2860
Vendor
Draytek
Product
Vigor2860 Firmware
Draytek
Vigor2860 Firmware
Vendor
Draytek
Product
Vigor2862
Draytek
Vigor2862
Vendor
Draytek
Product
Vigor2862 Firmware
Draytek
Vigor2862 Firmware
Vendor
Draytek
Product
Vigor2865
Draytek
Vigor2865
Vendor
Draytek
Product
Vigor2865 Firmware
Draytek
Vigor2865 Firmware
Vendor
Draytek
Product
Vigor2866
Draytek
Vigor2866
Vendor
Draytek
Product
Vigor2866 Firmware
Draytek
Vigor2866 Firmware
Vendor
Draytek
Product
Vigor2925
Draytek
Vigor2925
Vendor
Draytek
Product
Vigor2925 Firmware
Draytek
Vigor2925 Firmware
Vendor
Draytek
Product
Vigor2926
Draytek
Vigor2926
Vendor
Draytek
Product
Vigor2926 Firmware
Draytek
Vigor2926 Firmware
Vendor
Draytek
Product
Vigor2927
Draytek
Vigor2927
Vendor
Draytek
Product
Vigor2927 Firmware
Draytek
Vigor2927 Firmware
Vendor
Draytek
Product
Vigor2962
Draytek
Vigor2962
Vendor
Draytek
Product
Vigor2962 Firmware
Draytek
Vigor2962 Firmware
Vendor
Draytek
Product
Vigor3910
Draytek
Vigor3910
Vendor
Draytek
Product
Vigor3910 Firmware
Draytek
Vigor3910 Firmware
Vendor
Draytek
Product
Vigor3912
Draytek
Vigor3912
Vendor
Draytek
Product
Vigor3912 Firmware
Draytek
Vigor3912 Firmware
Vendor
Draytek
Product
Vigorlte200
Draytek
Vigorlte200
Vendor
Draytek
Product
Vigorlte200 Firmware
Draytek
Vigorlte200 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
