CVE-2024-41335: High severity DrayTek Vigor 165 vulnerability

Published Feb 27, 2025
·
Updated

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to utilize insecure versions of the functions strcmp and memcmp, allowing attackers to possibly obtain sensitive information via timing attacks.

Affected Software

21 affected components
DrayTek Vigor 165<4.2.6
DrayTek Vigor 166<4.2.6
DrayTek Vigor 2620<3.9.8.8
DrayTek LTE200<3.9.8.8
DrayTek Vigor 2860<3.9.7
DrayTek Vigor 2925<3.9.7
DrayTek Vigor 2862<3.9.9.4
DrayTek Vigor 2926<3.9.9.4
DrayTek Vigor 2133<3.9.8
DrayTek Vigor 2762<3.9.8
DrayTek Vigor 2832<3.9.8
DrayTek Vigor 2135<4.4.5.1
DrayTek Vigor 2765<4.4.5.1
DrayTek Vigor 2766<4.4.5.1
DrayTek Vigor 2865<4.4.5.3
DrayTek Vigor 2866<4.4.5.3
DrayTek Vigor 2927<4.4.5.3
DrayTek Vigor 2962<4.3.2.7
DrayTek Vigor 3910<4.3.2.7
DrayTek Vigor 3912<4.3.5.2
DrayTek Vigor 2925<=3.9.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Draytek Vigor 165/166 to a version that resolves this vulnerability.

    Fixed in 4.2.6
  2. Upgrade

    Upgrade Draytek Vigor 2620/LTE200 to a version that resolves this vulnerability.

    Fixed in 3.9.8.8
  3. Upgrade

    Upgrade Draytek Vigor 2860/2925 to a version that resolves this vulnerability.

    Fixed in 3.9.7
  4. Upgrade

    Upgrade Draytek Vigor 2862/2926 to a version that resolves this vulnerability.

    Fixed in 3.9.9.4
  5. Upgrade

    Upgrade Draytek Vigor 2133/2762/2832 to a version that resolves this vulnerability.

    Fixed in 3.9.8
  6. Upgrade

    Upgrade Draytek Vigor 2135/2765/2766 to a version that resolves this vulnerability.

    Fixed in 4.4.5.1
  7. Upgrade

    Upgrade Draytek Vigor 2865/2866/2927 to a version that resolves this vulnerability.

    Fixed in 4.4.5.3
  8. Upgrade

    Upgrade Draytek Vigor 2962/3910 to a version that resolves this vulnerability.

    Fixed in 4.3.2.7
  9. Upgrade

    Upgrade Draytek Vigor 3912 to a version that resolves this vulnerability.

    Fixed in 4.3.5.2
  10. Upgrade

    Upgrade Draytek Vigor 2925 to a version that resolves this vulnerability.

    Fixed in 3.9.6

Event History

Feb 27, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-41335?

CVE-2024-41335 has been classified with a severity level that varies based on the specific Draytek device affected.

2

How do I fix CVE-2024-41335?

To address CVE-2024-41335, users should update their Draytek devices to the latest firmware version as specified in the vendor recommendations.

3

Which Draytek devices are affected by CVE-2024-41335?

CVE-2024-41335 affects several Draytek devices including Vigor 165, 166, 2620, LTE200, 2860, 2925, and more, listed with their respective version requirements.

4

How can I verify if my Draytek device is vulnerable to CVE-2024-41335?

Users can check the firmware version of their Draytek device against the version requirements outlined for CVE-2024-41335 to determine vulnerability.

5

What kind of attacks does CVE-2024-41335 facilitate?

CVE-2024-41335 could potentially allow unauthorized access or manipulation of the affected Draytek devices, posing security risks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203