draytek
Security Risk Profile
65
/100
highSecurity Risk Score
Comprehensive risk assessment based on 141 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from October 22, 2013 to present
141
Total CVEs
123
Critical+High
7
Exploited
121
Unpatched
Threat Assessment
Avg CVSS
8.1
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
121
Critical/High
Risk Level
65/100
high
⚠️ 7 Active Exploits
Severity Distribution
Critical
29High
94Medium
15Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
Buffer Overflow
51
2
Command Injection
37
3
OS Command Injection
33
4
XSS
10
5
Path Traversal
7
Most Affected Products
1. DrayTek Vigor3910 Firmware69
2. DrayTek Vigor2962 Firmware32
3. DrayTek Vigor2960 Firmware32
4. DrayTek Vigor300b Firmware29
5. DrayTek Vigor3900 Firmware29
Recent Vulnerabilities
See more →CVE-2022-50994
CVSS 9.2critical
DrayTek Vigor 2960 < 1.5.1.4 OS Command Injection via mainfunction.cgi
5/8/2026🔧 No Patch
CVE-2026-3040
CVSS 7.2EPSS 0%high
DrayTek Vigor 300B Web Management uploadlangs cgiGetFile os command injection
2/23/2026🔧 No Patch
https://www.bleepingcomputer.com/news/security/draytek-warns-of-remote-code-execution-bug-in-vigor-routers/
unknown
DrayTek warns of remote code execution bug in Vigor routers
10/2/2025⚠ Exploited🔧 No Patch
CVE-2025-44643
CVSS 8.6high
8/4/2025🔧 No Patch
https://www.theregister.com/2025/03/25/draytek_routers_bootloop/
unknown
Something's thrown DrayTek routers into a bootloop
3/25/2025⚠ Exploited🔧 No Patch
CVE-2024-41338
CVSS 7.5high
2/27/2025🔧 No Patch
CVE-2024-41335
CVSS 7.5high
2/27/2025🔧 No Patch
CVE-2024-41336
CVSS 7.5high
2/27/2025🔧 No Patch
CVE-2024-41339
CVSS 8.8high
2/27/2025🔧 No Patch
CVE-2024-41334
CVSS 8.8high
2/27/2025🔧 No Patch
Monitor draytek in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.