CVE-2024-41339
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2024-41339 is a critical vulnerability affecting various Draytek devices, including Vigor 165/166, Vigor 2620/LTE200, Vigor 2860/2925, Vigor 2862/2926, Vigor 2133/2762/2832, Vigor 2135/2765/2766, Vigor 2865/2866/2927, Vigor 2962/3910, Vigor 3912, and Vigor 2925. With this vulnerability, attackers can exploit a flaw in the CGI endpoint used for configuration uploads and inject a crafted kernel module. This allows for arbitrary code execution and potential unauthorized access or system takeover. Device users are urged to update their firmware to the latest versions available to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.