Known vulnerabilities in Vigor2866 LTE
Vendor:
DrayTek Corp.
Software:
Vigor2866 LTE
Software CPE:
cpe:2.3:h:draytek_corp:vigor2866_lte:*:*:*:*:*:*:*:*
Website:
https://www.draytek.co.uk
Total vulnerabilities:
12
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (12)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU116451 - Use of Uninitialized Variable CVE-2025-10547 |
CWE-457 | Critical | 4.5.1 | 04.10.2025 |
SB2025100409 |
||
| #VU106357 - Unrestricted Upload of File with Dangerous Type CVE-2024-41340 |
CWE-434 | High | 4.4.5.3 | 01.04.2025 |
SB2025040126 |
||
| #VU106355 - NULL Pointer Dereference CVE-2024-41338 |
CWE-476 | High | 4.4.5.3 | 01.04.2025 |
SB2025040126 |
||
| #VU106354 - Unprotected Storage of Credentials CVE-2024-41336 |
CWE-256 | Low | 4.4.5.3 | 01.04.2025 |
SB2025040126 |
||
| #VU106353 - Observable discrepancy CVE-2024-41335 |
CWE-203 | High | 4.4.5.3 | 01.04.2025 |
SB2025040126 |
||
| #VU106352 - Improper Control of Generation of Code ('Code Injection') CVE-2024-41339 |
CWE-94 | High | 4.4.5.3 | 01.04.2025 |
SB2025040126 |
||
| #VU106351 - Improper Certificate Validation CVE-2024-41334 |
CWE-295 | High | 4.4.5.3 | 01.04.2025 |
SB2025040126 |
||
| #VU106350 - Integer overflow CVE-2024-51139 |
CWE-190 | High | 4.4.5.8 | 01.04.2025 |
SB2025040124 |
||
| #VU106349 - Stack-based buffer overflow CVE-2024-51138 |
CWE-121 | High | 4.4.5.8 | 01.04.2025 |
SB2025040124 |
||
| #VU103559 - Out-of-bounds write CVE-2025-20633 |
CWE-787 | High | 4.4.6.1 | 04.02.2025 |
SB2025020401 SB2025040837 |
||
| #VU103560 - Out-of-bounds write CVE-2025-20632 |
CWE-787 | Low | 4.4.6.1 | 04.02.2025 |
SB2025020401 SB2025040837 |
||
| #VU103561 - Out-of-bounds write CVE-2025-20631 |
CWE-787 | Low | 4.4.6.1 | 04.02.2025 |
SB2025020401 SB2025040837 |