#VU106349 Stack-based buffer overflow in DrayTek Corp. products - CVE-2024-51138
Published: April 1, 2025
Vigor2620 LTE
VigorLTE 200n
Vigor2133
Vigor2135
Vigor2762
Vigor2765
Vigor2766
Vigor2832
Vigor2860
Vigor2860 LTE
Vigor2862
Vigor2862 LTE
Vigor2865
Vigor2865 LTE
Vigor2865L-5G
Vigor2866
Vigor2866 LTE
Vigor2915
Vigor2925
Vigor2925 LTE
Vigor2926
Vigor2926 LTE
Vigor2927
Vigor2927 LTE
Vigor2927L-5G
Vigor2952
Vigor2952P
Vigor2962
Vigor3220
Vigor3910
Vigor3912
DrayTek Corp.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in the URL parsing functionality of the TR069 STUN server. A remote unauthenticated attacker can send a specially crafted request, trigger stack-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.