Arbitrary Code Execution Vulnerability in Draytek Vigor Devices
CVE-2024-41340

8.4HIGH

Key Information:

Vendor

Draytek

Vendor
CVE Published:
27 February 2025

What is CVE-2024-41340?

Draytek Vigor Routers are susceptible to a significant vulnerability that permits attackers to upload specially crafted APP Enforcement modules. This flaw can lead to arbitrary code execution, jeopardizing the integrity and confidentiality of the affected systems. Users of Vigor 165/166, Vigor 2620/LTE200, and several other models are encouraged to upgrade to the latest firmware versions to mitigate this risk.

References

CVSS V3.1

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-41340 : Arbitrary Code Execution Vulnerability in Draytek Vigor Devices