CVE-2025-10547: DrayTek Corporation VIGOR1000B

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.

Affected products

Published 2025-10-03. Last modified 2026-06-17.