Description

An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload a crafted kernel module, allowing for arbitrary code execution.

INFO

Published Date :

2025-02-27T00:00:00.000Z

Last Modified :

2025-05-06T18:07:42.843Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-41339 vulnerability.

Vendors Products
Draytek
  • Vigor165
  • Vigor165 Firmware
  • Vigor166
  • Vigor166 Firmware
  • Vigor2133
  • Vigor2133 Firmware
  • Vigor2135
  • Vigor2135 Firmware
  • Vigor2620
  • Vigor2620 Firmware
  • Vigor2762
  • Vigor2762 Firmware
  • Vigor2765
  • Vigor2765 Firmware
  • Vigor2766
  • Vigor2766 Firmware
  • Vigor2832
  • Vigor2832 Firmware
  • Vigor2860
  • Vigor2860 Firmware
  • Vigor2862
  • Vigor2862 Firmware
  • Vigor2865
  • Vigor2865 Firmware
  • Vigor2866
  • Vigor2866 Firmware
  • Vigor2925
  • Vigor2925 Firmware
  • Vigor2926
  • Vigor2926 Firmware
  • Vigor2927
  • Vigor2927 Firmware
  • Vigor2962
  • Vigor2962 Firmware
  • Vigor3910
  • Vigor3910 Firmware
  • Vigor3912
  • Vigor3912 Firmware
  • Vigorlte200
  • Vigorlte200 Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-41339.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact