CVE-2024-41590

CVSS 3.1 Score 8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Oct 7, 2024
CWE ID 121

Summary

CVE-2024-41590 represents a buffer overflow vulnerability affecting several CGI endpoints on DrayTek Vigor310 devices up to version 4.3.2.6. This issue allows authenticated users to overwrite memory by passing large inputs to the strcpy function in POST requests, leading to potential code injection and serious security consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share