SB2022080516 - Remote code execution in DrayTek Vigor routers
Published: August 5, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Buffer overflow (CVE-ID: CVE-2022-32548)
The vulnerability allows a remote attacker to execute arbitrary code on the target device.
The vulnerability exists due to a boundary error in the login page at "/cgi-bin/wlogin.cgi" script within the web management interface. A remote attacker can send a specially crafted base64-encoded payload via HTTP POST request to the affected script, trigger memory corruption and execute arbitrary code on the device.
Remediation
Install update from vendor's website.