Known vulnerabilities in Vigor165
Vendor:
DrayTek Corp.
Software:
Vigor165
Software CPE:
cpe:2.3:h:draytek_corp:vigor165:*:*:*:*:*:*:*:*
Website:
https://www.draytek.co.uk
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU106357 - Unrestricted Upload of File with Dangerous Type CVE-2024-41340 |
CWE-434 | High | 4.2.7 | 01.04.2025 |
SB2025040126 |
||
| #VU106355 - NULL Pointer Dereference CVE-2024-41338 |
CWE-476 | High | 4.2.7 | 01.04.2025 |
SB2025040126 |
||
| #VU106354 - Unprotected Storage of Credentials CVE-2024-41336 |
CWE-256 | Low | 4.2.7 | 01.04.2025 |
SB2025040126 |
||
| #VU106353 - Observable discrepancy CVE-2024-41335 |
CWE-203 | High | 4.2.7 | 01.04.2025 |
SB2025040126 |
||
| #VU106352 - Improper Control of Generation of Code ('Code Injection') CVE-2024-41339 |
CWE-94 | High | 4.2.7 | 01.04.2025 |
SB2025040126 |
||
| #VU106351 - Improper Certificate Validation CVE-2024-41334 |
CWE-295 | High | 4.2.7 | 01.04.2025 |
SB2025040126 |