CVE-2025-10547
An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.
Published:Oct 3, 2025
Last Modified:Apr 15, 2026
EPS:Oct 3, 2025
EPSS Score:0.00061
CVSS Score:9.8
Affected Products
Vendor
Product
Action
Vendor
Draytek
Product
Drayos
Draytek
Drayos
Vendor
Draytek
Product
Vigor1000b
Draytek
Vigor1000b
Vendor
Draytek
Product
Vigor2135
Draytek
Vigor2135
Vendor
Draytek
Product
Vigor2763
Draytek
Vigor2763
Vendor
Draytek
Product
Vigor2765
Draytek
Vigor2765
Vendor
Draytek
Product
Vigor2766
Draytek
Vigor2766
Vendor
Draytek
Product
Vigor2862
Draytek
Vigor2862
Vendor
Draytek
Product
Vigor2865
Draytek
Vigor2865
Vendor
Draytek
Product
Vigor Routers
Draytek
Vigor Routers
Exploits
No exploit reference
Common Weakness Enumeration
No CWE recorded yet
Common Attack Pattern Enumeration and Classification (CAPEC)
No CAPEC recorded yet
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
