The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function.
References
Configurations
No configuration.
History
No history.
Information
Published : 2024-10-03 19:15
Updated : 2024-10-07 19:37
NVD link : CVE-2024-41588
Mitre link : CVE-2024-41588
CVE.ORG link : CVE-2024-41588
JSON object : View
Products Affected
No product.
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')