CVE-2022-32548
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
Affected (68)
Products: Draytek: Vigor3910 Firmware, Vigor1000b Firmware, Vigor2962 Firmware, Vigor2962p Firmware, Vigor2927 Firmware, Vigor2927ax Firmware, Vigor2927ac Firmware, Vigor2927vac Firmware, Vigor2927l Firmware, Vigor2927lac Firmware, Vigor2915 Firmware, Vigor2915ac Firmware, Vigor2952 Firmware, Vigor2952p Firmware, Vigor3220 Firmware, Vigor2926 Firmware, Vigor2926n Firmware, Vigor2926ac Firmware, Vigor2926vac Firmware, Vigor2926l Firmware, Vigor2926ln Firmware, Vigor2926lac Firmware, Vigor2862 Firmware, Vigor2862n Firmware, Vigor2862ac Firmware, Vigor2862vac Firmware, Vigor2862b Firmware, Vigor2862bn Firmware, Vigor2862l Firmware, Vigor2862ln Firmware, Vigor2862lac Firmware, Vigor2620l Firmware, Vigor2620ln Firmware, Vigorlte 200n Firmware, Vigor2133 Firmware, Vigor2133n Firmware, Vigor2133ac Firmware, Vigor2133vac Firmware, Vigor2133fvac Firmware, Vigor2762 Firmware, Vigor2762n Firmware, Vigor2762ac Firmware, Vigor2762vac Firmware, Vigor165 Firmware, Vigor166 Firmware, Vigor2135 Firmware, Vigor2135ac Firmware, Vigor2135vac Firmware, Vigor2135fvac Firmware, Vigor2765 Firmware, Vigor2765ac Firmware, Vigor2765vac Firmware, Vigor2766 Firmware, Vigor2766ac Firmware, Vigor2766vac Firmware, Vigor2832 Firmware, Vigor2865 Firmware, Vigor2865ax Firmware, Vigor2865ac Firmware, Vigor2865vac Firmware, Vigor2865l Firmware, Vigor2865lac Firmware, Vigor2866 Firmware, Vigor2866ax Firmware, Vigor2866ac Firmware, Vigor2866vac Firmware, Vigor2866l Firmware, Vigor2866lac Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.1.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor3910 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.1.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor1000b | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.1.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2962 | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.1.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2962p | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2927 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2927ax | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2927ac | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2927vac | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2927l | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2927lac | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.3.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2915 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.3.3.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2915ac | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.7.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2952 | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.7.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2952p | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.7.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor3220 | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926 | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926n | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926ac | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926vac | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926l | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926ln | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2926lac | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862 | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862n | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862ac | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862vac | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862b | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862bn | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862l | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862ln | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2862lac | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2620l | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2620ln | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.8.1 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigorlte 200n | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2133 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2133n | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2133ac | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2133vac | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2133fvac | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2762 | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2762n | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2762ac | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2762vac | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor165 | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.2.4 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor166 | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2135 | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2135ac | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2135vac | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2135fvac | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2765 | All versions |
Configuration Y
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2765ac | All versions |
Configuration Z
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2765vac | All versions |
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2766 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2766ac | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.2 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2766vac | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.9.6 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2832 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2865 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2865ax | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2865ac | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2865vac | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2865l | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2865lac | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2866 | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2866ax | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2866ac | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2866vac | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2866l | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.4.0 |
| Running on/with | Platform Versions |
|---|---|
Draytek Vigor2866lac | All versions |
References (4)
Source: cve@mitre.org
ExploitThird Party Advisory
Source: cve@mitre.org
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Timeline
No history available yet.