CVE-2024-41595

CVSS 3.1 Score 8 of 10 (high)

Details

Published Oct 3, 2024
Updated: Oct 4, 2024
CWE ID 125
CWE ID 787

Summary

CVE-2024-41595 is a vulnerability affecting DrayTek Vigor310 devices up to version 4.3.2.6. An attacker can exploit this issue by remotely altering settings or causing a denial of service through .cgi pages. The root cause is a lack of bounds checking on read and write operations in these pages, allowing an adversary to exceed intended limits and execute unintended actions. This vulnerability poses a significant risk, particularly for organizations relying on these devices for network connectivity and security. Immediate patching is recommended to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share