CVE-2024-41586: DrayTek VIGOR3910 Firmware
High severity, CVSS 8.0. EPSS: 0.5% chance of exploitation in the next 30 days.
A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.
Affected products
- DrayTek VIGOR3910 Firmware: up to and including 4.3.2.6
Published 2024-10-03. Last modified 2026-06-17.