CVE-2024-41590
CVE-2024-41590 is a buffer overflow vulnerability affecting DrayTek Vigor310 devices up to firmware version 4.3.2.6. Authenticated users can exploit this flaw by sending specially crafted POST requests to vulnerable CGI endpoints, triggering a buffer overflow due to missing bounds checking when copying parameters using the strcpy function. While the CVSS score is 0, indicating a base severity of None, this does not fully represent the risk. SOCRadar's Vulnerability Risk Score (SVRS) is 30, suggesting a low risk. Despite the lower SVRS, the potential for remote code execution exists if the overflow is successfully exploited. The vulnerability lies in CWE-121 (Stack-based Buffer Overflow). Organizations using affected DrayTek devices should apply available patches or mitigations to prevent potential exploitation and ensure system security. The vulnerability is tagged "In The Wild" so there is a risk of exploitation.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.