Use of uninitialized variable in DrayTek Corp. products - CVE-2025-10547

 

Use of uninitialized variable in DrayTek Corp. products - CVE-2025-10547

Published: October 4, 2025


Vulnerability identifier: #VU116451
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-10547
CWE-ID: CWE-457
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the affected device. 

The vulnerability exists due to usage of an uninitialized variable within the device's Web User Interface (WebUI). A remote non-authenticated attacker can send a specially crafted HTTP request to the web interface of the affected device, trigger memory corruption and execute arbitrary code on the system.


Affected software

Vigor2925 LTE
Vigor2925
Vigor2860 LTE
Vigor2860
Vigor2952
Vigor2952P
Vigor3220
Vigor2832
Vigor2762
Vigor2133
VigorLTE 200n
Vigor2620
Vigor2926 LTE
Vigor2926
Vigor2862 LTE
Vigor2862
Vigor2962
Vigor3910
Vigor3912
Vigor2915
Vigor2766
Vigor2135
Vigor2763
Vigor2765
Vigor2927 LTE
Vigor2865
Vigor2865 LTE
Vigor2865L-5G
Vigor2866
Vigor2866 LTE
Vigor2927
Vigor2927L-5G
Vigor 1000B

How to mitigate CVE-2025-10547

Install updates from vendor's website.

Vigor2925 LTE - update to 3.9.8.6
Vigor2925 - update to 3.9.8.6
Vigor2860 LTE - update to 3.9.8.6
Vigor2860 - update to 3.9.8.6
Vigor2952 - update to 3.9.8.8
Vigor2952P - update to 3.9.8.8
Vigor3220 - update to 3.9.8.8
Vigor2832 - update to 3.9.9.4
Vigor2762 - update to 3.9.9.4
Vigor2133 - update to 3.9.9.4
VigorLTE 200n - update to 3.9.9.5
Vigor2620 - update to 3.9.9.5
Vigor2926 LTE - update to 3.9.9.12
Vigor2926 - update to 3.9.9.12
Vigor2862 LTE - update to 3.9.9.12
Vigor2862 - update to 3.9.9.12
Vigor2962 - addressed in versions 4.4.3.6, 4.4.5.1
Vigor 1000B - update to 4.4.3.6
Vigor3910 - addressed in versions 4.4.3.6, 4.4.5.1
Vigor3912 - addressed in versions 4.4.3.6, 4.4.5.1
Vigor2915 - update to 4.4.6.1
Vigor2766 - update to 4.5.1
Vigor2135 - update to 4.5.1
Vigor2763 - update to 4.5.1
Vigor2765 - update to 4.5.1
Vigor2927 LTE - update to 4.5.1
Vigor2865 - update to 4.5.1
Vigor2865 LTE - update to 4.5.1
Vigor2865L-5G - update to 4.5.1
Vigor2866 - update to 4.5.1
Vigor2866 LTE - update to 4.5.1
Vigor2927 - update to 4.5.1
Vigor2927L-5G - update to 4.5.1

External References

Related Security Bulletins