CVE-2024-41340
CVSS 3.1 Score 8.4 of 10 (high)
Details
Published Feb 27, 2025
Updated: Feb 28, 2025
CWE ID 434
Summary
CVE-2024-41340 is a vulnerability affecting several Draytek device models, including Vigor 165/166, Vigor 2620/LTE200, Vigor 2860/2925, Vigor 2862/2926, Vigor 2133/2762/2832, Vigor 2135/2765/2766, Vigor 2865/2866/2927, Vigor 2962/3910, Vigor 3912, and Vigor 2925. This issue allows attackers to upload custom APP Enforcement modules, which can result in arbitrary code execution on the affected devices. Users are advised to update their devices to the recommended firmware versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.