CVE Feed

    Dashboard / CVE / CVE-2024-41593

    CVE-2024-41593

    DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.

    Published:Oct 3, 2024
    Last Modified:Mar 13, 2025
    EPS:Oct 3, 2024
    EPSS Score:0.02292
    CVSS Score:9.8

    Affected Products

    Vendor
    Draytek
    Product
    Vigor1000b
    Vendor
    Draytek
    Product
    Vigor1000b Firmware
    Vendor
    Draytek
    Product
    Vigor165
    Vendor
    Draytek
    Product
    Vigor165 Firmware
    Vendor
    Draytek
    Product
    Vigor166
    Vendor
    Draytek
    Product
    Vigor166 Firmware
    Vendor
    Draytek
    Product
    Vigor2133
    Vendor
    Draytek
    Product
    Vigor2133 Firmware
    Vendor
    Draytek
    Product
    Vigor2135
    Vendor
    Draytek
    Product
    Vigor2135 Firmware
    Vendor
    Draytek
    Product
    Vigor2620
    Vendor
    Draytek
    Product
    Vigor2620 Firmware
    Vendor
    Draytek
    Product
    Vigor2762
    Vendor
    Draytek
    Product
    Vigor2762 Firmware
    Vendor
    Draytek
    Product
    Vigor2763
    Vendor
    Draytek
    Product
    Vigor2763 Firmware
    Vendor
    Draytek
    Product
    Vigor2765
    Vendor
    Draytek
    Product
    Vigor2765 Firmware
    Vendor
    Draytek
    Product
    Vigor2766
    Vendor
    Draytek
    Product
    Vigor2766 Firmware
    Vendor
    Draytek
    Product
    Vigor2832
    Vendor
    Draytek
    Product
    Vigor2832 Firmware
    Vendor
    Draytek
    Product
    Vigor2860
    Vendor
    Draytek
    Product
    Vigor2860 Firmware
    Vendor
    Draytek
    Product
    Vigor2862
    Vendor
    Draytek
    Product
    Vigor2862 Firmware
    Vendor
    Draytek
    Product
    Vigor2865
    Vendor
    Draytek
    Product
    Vigor2865 Firmware
    Vendor
    Draytek
    Product
    Vigor2866
    Vendor
    Draytek
    Product
    Vigor2866 Firmware
    Vendor
    Draytek
    Product
    Vigor2915
    Vendor
    Draytek
    Product
    Vigor2915 Firmware
    Vendor
    Draytek
    Product
    Vigor2925
    Vendor
    Draytek
    Product
    Vigor2925 Firmware
    Vendor
    Draytek
    Product
    Vigor2926
    Vendor
    Draytek
    Product
    Vigor2926 Firmware
    Vendor
    Draytek
    Product
    Vigor2952
    Vendor
    Draytek
    Product
    Vigor2952 Firmware
    Vendor
    Draytek
    Product
    Vigor2962
    Vendor
    Draytek
    Product
    Vigor2962 Firmware
    Vendor
    Draytek
    Product
    Vigor3220
    Vendor
    Draytek
    Product
    Vigor3220 Firmware
    Vendor
    Draytek
    Product
    Vigor3910
    Vendor
    Draytek
    Product
    Vigor3910 Firmware
    Vendor
    Draytek
    Product
    Vigor3912
    Vendor
    Draytek
    Product
    Vigor3912 Firmware
    Vendor
    Draytek
    Product
    Vigorlte200
    Vendor
    Draytek
    Product
    Vigorlte200 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High