VULNERABILITY INTELLIGENCE
CVE-2024-41595
CVSS score8 HIGH
EPSS probability0.34%
CISA KEVNot currently listed
Published2024-10-03
Last modified2026-06-17
CVSS vectorCVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.
Weakness classification
- CWE-125: Out-of-bounds Read
- CWE-787: Out-of-bounds Write
Primary references
- cve@mitre.org — Third Party Advisory
- cve@mitre.org — Broken Link