CVE-2024-41588: Buffer Overflow
The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41588?
CVE-2024-41588 is classified as a high severity vulnerability due to potential exploitation by authenticated users.
How do I fix CVE-2024-41588?
To fix CVE-2024-41588, update the DrayTek Vigor3910 firmware to version 4.3.2.7 or later.
What impact does CVE-2024-41588 have?
CVE-2024-41588 can lead to buffer overflow attacks, potentially allowing attackers to execute arbitrary code.
Who is affected by CVE-2024-41588?
CVE-2024-41588 affects users of DrayTek Vigor3910 devices running firmware version 4.3.2.6 or earlier.
Is authentication required to exploit CVE-2024-41588?
Yes, authentication is required to exploit CVE-2024-41588, as it targets authenticated users.