CVE-2024-41590: Buffer Overflow
Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41590?
CVE-2024-41590 is considered a high severity vulnerability due to the potential for authenticated users to exploit it.
How do I fix CVE-2024-41590?
To fix CVE-2024-41590, update your DrayTek Vigor310 device firmware to a version beyond 4.3.2.6.
Who is affected by CVE-2024-41590?
Authenticated users on DrayTek Vigor310 devices running version 4.3.2.6 or earlier are affected by CVE-2024-41590.
What is the nature of the vulnerability in CVE-2024-41590?
CVE-2024-41590 involves a buffer overflow due to missing bounds checking on parameters in POST requests.
What types of attacks can CVE-2024-41590 enable?
CVE-2024-41590 can enable authenticated attackers to execute arbitrary code or cause denial-of-service conditions.