Arbitrary Code Execution Vulnerability in Draytek Vigor Devices
CVE-2024-41340
Currently unrated
Summary
Draytek Vigor Routers are susceptible to a significant vulnerability that permits attackers to upload specially crafted APP Enforcement modules. This flaw can lead to arbitrary code execution, jeopardizing the integrity and confidentiality of the affected systems. Users of Vigor 165/166, Vigor 2620/LTE200, and several other models are encouraged to upgrade to the latest firmware versions to mitigate this risk.
References
Timeline
Vulnerability published
Vulnerability Reserved