Insecure Function Implementations in Draytek Vigor Routers and Devices
CVE-2024-41335

Currently unrated

Key Information:

Vendor
Draytek
Vendor
CVE Published:
27 February 2025

Summary

Multiple Draytek Vigor devices have been identified as using insecure implementations of the functions strcmp and memcmp. These vulnerabilities can be exploited by attackers to perform timing attacks, potentially leading to the exposure of sensitive information. It is crucial for users to upgrade affected devices to secure versions to mitigate these risks.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.