Vigor 1000b
18 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Vigor 1000b, a product in the networking infrastructure space. Use it to gauge the current risk picture and drill into individual advisories.
Vigor 1000b CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 14 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 1 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical5
- High8
- Medium5
Latest CVEs
The 15 most recently published vulnerabilities affecting Vigor 1000b.
- CVE-2025-10547CVE-2025-105479.8
- CVE-2024-41586A stack-based Buffer Overflow vulnerability in DrayTek Vigor310 devices through 4.3.2.6 allows a remote attacker to execute arbitrary code via a long query string to the cgi-bin/ipfedr.cgi component.8.0
- CVE-2024-41595DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.8.0
- CVE-2024-41594An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG...7.5
- CVE-2024-41596Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters.8.0
- CVE-2024-41591DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.6.1
- CVE-2024-41590Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vig...8.0
- CVE-2024-41583DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.4.7
- CVE-2024-41587Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.5.4
- CVE-2024-41593DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument ...9.8
- CVE-2024-41589DrayTek Vigor310 devices through 4.3.2.6 use unencrypted HTTP for authentication requests.8.8
- CVE-2024-41588The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters ...8.0
- CVE-2024-41585DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and injec...6.8
- CVE-2024-41584DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to reflected XSS by authenticated users, caused by missing validation of the sFormAuthStr parameter.4.7
- CVE-2024-41592DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.8.0
Product grouping is registry-driven, with AI assist and human review. How it works