CVE-2025-10547: DrayTek Corporation VIGOR1000B
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.
Affected products
- DrayTek Corporation VIGOR1000B: before 4.4.5.1 (fixed in 4.4.5.1)
- DrayTek Corporation VIGOR2135: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2763: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2765: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2766: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2862: before 3.9.9.12 (fixed in 3.9.9.12)
- DrayTek Corporation VIGOR2862 Lte: before 3.9.9.12 (fixed in 3.9.9.12)
- DrayTek Corporation VIGOR2865: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2865 Lte Series: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2865L-5g Series: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2866: from 1.0, before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2866 Lte: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2915: before 4.4.6.1 (fixed in 4.4.6.1)
- DrayTek Corporation VIGOR2926: before 3.9.9.12 (fixed in 3.9.9.12)
- DrayTek Corporation VIGOR2927: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2927L-5g: before 4.5.1 (fixed in 4.5.1)
- DrayTek Corporation VIGOR2962: before 4.4.5.1 (fixed in 4.4.5.1)
- DrayTek Corporation VIGOR3910: before 4.4.3.6 (fixed in 4.4.3.6)
- DrayTek Corporation VIGOR3912: before 4.4.5.1 (fixed in 4.4.5.1)
- DrayTek Corporation Vigor 2927 Lte: before 4.5.1 (fixed in 4.5.1)
Published 2025-10-03. Last modified 2026-06-17.