CVE-2024-41592: High severity draytek vigor routers vulnerability
DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41592?
CVE-2024-41592 is considered a high-severity vulnerability due to its potential for remote exploitation and system compromise.
How do I fix CVE-2024-41592?
To fix CVE-2024-41592, update your DrayTek Vigor3910 device to the latest firmware version beyond 4.3.2.6.
What is the nature of the vulnerability in CVE-2024-41592?
CVE-2024-41592 involves a stack-based overflow caused by mishandling query string parameters in the GetCGI function.
What devices are affected by CVE-2024-41592?
CVE-2024-41592 affects DrayTek Vigor3910 devices running firmware version 4.3.2.6 or earlier.
Can CVE-2024-41592 be exploited remotely?
Yes, CVE-2024-41592 can be exploited remotely, allowing attackers to execute arbitrary code on the affected devices.