Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability · Added 2026-08-11 · Due 2026-08-14CISA KEV · CVE-2026-68820 · Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability · Added 2026-08-11 · Due 2026-08-25

Vendors · draytek

draytek

· 27 Critical

Total CVEs

134

Critical

27

Products

280

Search All CVEs →

134

Products (280)

vigor3910 firmware60 CVEsvigor391060 CVEsvigor3900 firmware48 CVEsvigor390048 CVEsvigor296021 CVEsvigor2960 firmware21 CVEsvigor296217 CVEsvigor300b17 CVEsvigor300b firmware17 CVEsvigor2962 firmware17 CVEsvigor2925 firmware17 CVEsvigor2765 firmware16 CVEsvigor283216 CVEsvigor2832 firmware16 CVEsvigor286216 CVEsvigor2862 firmware16 CVEsvigor276216 CVEsvigor2762 firmware16 CVEsvigor213316 CVEsvigor2133 firmware16 CVEsvigor213516 CVEsvigor2135 firmware16 CVEsvigor276516 CVEsvigor286516 CVEsvigor2865 firmware16 CVEsvigor292616 CVEsvigor2926 firmware16 CVEsvigor276616 CVEsvigor286616 CVEsvigor2866 firmware16 CVEsvigor2766 firmware16 CVEsvigor292515 CVEsvigor2860 firmware15 CVEsvigor286015 CVEsvigor166 firmware15 CVEsvigor262015 CVEsvigor16515 CVEsvigor165 firmware15 CVEsvigor16615 CVEsvigor2620 firmware15 CVEsvigor3912 firmware14 CVEsvigorlte200 firmware14 CVEsvigorlte20014 CVEsvigor391214 CVEsvigor1000b firmware13 CVEsvigor1000b13 CVEsvigor3220 firmware12 CVEsvigor295212 CVEsvigor2952 firmware12 CVEsvigor322012 CVEsvigor2915 firmware12 CVEsvigor291512 CVEsvigor276311 CVEsvigor2763 firmware11 CVEsvigor2927 firmware8 CVEsvigor29278 CVEsvigorconnect7 CVEsvigorap 910c firmware4 CVEsvigorap 910c4 CVEsvigor2865lac firmware3 CVEsvigor2865vac3 CVEsvigor2865vac firmware3 CVEsvigor2866ac3 CVEsvigor2866ac firmware3 CVEsvigor2866ax firmware3 CVEsvigor2866ax3 CVEsvigor2866l3 CVEsvigor2866l firmware3 CVEsvigor2866lac3 CVEsvigor2866lac firmware3 CVEsvigor2866vac3 CVEsvigor2866vac firmware3 CVEsvigor2915ac3 CVEsvigor2915ac firmware3 CVEsvigor2925ac3 CVEsvigor2925fn3 CVEsvigor2927vac firmware3 CVEsvigor2927vac3 CVEsvigor2927lac firmware3 CVEsvigor2927lac3 CVEsvigor2925n-plus3 CVEsvigor2927l firmware3 CVEsvigor2927l3 CVEsvigor2925vac3 CVEsvigor2927ax firmware3 CVEsvigor2925vn-plus3 CVEsvigor2927ax3 CVEsvigor2927ac firmware3 CVEsvigor2927ac3 CVEsvigor2135ac3 CVEsvigor2135ac firmware3 CVEsvigor2765ac3 CVEsvigor2765ac firmware3 CVEsvigor2135fvac3 CVEsvigor2135fvac firmware3 CVEsvigor2135vac3 CVEsvigor2135vac firmware3 CVEsvigor2766ac3 CVEsvigor2766ac firmware3 CVEsvigor2766vac3 CVEsvigor2766vac firmware3 CVEsvigor2862ac3 CVEsvigor2862ac firmware3 CVEsvigor2862b3 CVEsvigor2862b firmware3 CVEsvigor2862bn3 CVEsvigor2862bn firmware3 CVEsvigor2862l3 CVEsvigor2862l firmware3 CVEsvigor2862lac3 CVEsvigor2862lac firmware3 CVEsvigor2862ln3 CVEsvigor2862ln firmware3 CVEsvigor2862n3 CVEsvigor2862n firmware3 CVEsvigor2862vac3 CVEsvigor2862vac firmware3 CVEsvigor2865ac3 CVEsvigor2865ac firmware3 CVEsvigor2865ax3 CVEsvigor2865ax firmware3 CVEsvigor2865l3 CVEsvigor2865l firmware3 CVEsvigor2865lac3 CVEsvigorap 1000c2 CVEsvigor1302 CVEsvigor130 firmware2 CVEsvigor1672 CVEsvigor167 firmware2 CVEsvigor2133ac2 CVEsvigor2133ac firmware2 CVEsvigor2133fvac2 CVEsvigor2133fvac firmware2 CVEsvigor2133n2 CVEsvigor2133n firmware2 CVEsvigor2133vac2 CVEsvigor2133vac firmware2 CVEsvigor2135ax2 CVEsvigor2135ax firmware2 CVEsvigor2620l2 CVEsvigor2620l firmware2 CVEsvigor2620ln2 CVEsvigor2620ln firmware2 CVEsvigor2762ac2 CVEsvigor2762ac firmware2 CVEsvigor2762n2 CVEsvigor2762n firmware2 CVEsvigor2762vac2 CVEsvigor2762vac firmware2 CVEsvigor2763ac2 CVEsvigor2763ac firmware2 CVEsvigor2765ax2 CVEsvigor2765ax firmware2 CVEsvigor2765vac2 CVEsvigor2765vac firmware2 CVEsvigor2766ax2 CVEsvigor2766ax firmware2 CVEsvigor2832n2 CVEsvigor2832n firmware2 CVEsvigor2926ac2 CVEsvigor2926ac firmware2 CVEsvigor2926l2 CVEsvigor2926l firmware2 CVEsvigor2926lac2 CVEsvigor2926lac firmware2 CVEsvigor2926ln2 CVEsvigor2926ln firmware2 CVEsvigor2926n2 CVEsvigor2926n firmware2 CVEsvigor2926vac2 CVEsvigor2926vac firmware2 CVEsvigor2927f2 CVEsvigor2927f firmware2 CVEsvigor2952p2 CVEsvigor2952p firmware2 CVEsvigor2962p2 CVEsvigor2962p firmware2 CVEsvigor 29252 CVEsvigor 2925n2 CVEsvigor 29602 CVEsvigor 2960 firmware2 CVEsvigorap 1000c firmware2 CVEsvigorap 9032 CVEsvigorap 903 firmware2 CVEsvigorap 912c2 CVEsvigorap 912c firmware2 CVEsvigorap 918r2 CVEsvigorap 918r firmware2 CVEsvigorlte 200n2 CVEsvigorlte 200n firmware2 CVEsvigor2860vac firmware1 CVEsvigorswitch p1282 firmware1 CVEsvigorswitch p21001 CVEsvigor2860vac1 CVEsvigor2860n firmware1 CVEsvigor2860n-plus firmware1 CVEsvigor2860n-plus1 CVEsvigor2860n1 CVEsvigor2860ln firmware1 CVEsvigor2860ln1 CVEsvigor2860l firmware1 CVEsvigor2860l1 CVEsvigor2860ac firmware1 CVEsvigor 2700 router1 CVEsvigor 2700 router firmware1 CVEsvigorswitch p2100 firmware1 CVEsvigorswitch p2280x1 CVEsvigorswitch p2280x firmware1 CVEsvigorswitch p2540xs1 CVEsmyvigor1 CVEsvigorswitch p2540xs firmware1 CVEsvigorap 1060c1 CVEsvigorap 1060c firmware1 CVEsvigorap 7001 CVEsvigorap 700 firmware1 CVEsvigorap 7101 CVEsvigorap 710 firmware1 CVEsvigorap 8001 CVEsvigorap 800 firmware1 CVEsvigorap 8021 CVEsvigorap 802 firmware1 CVEsvigorap 8101 CVEsvigorap 810 firmware1 CVEsvigorap 9001 CVEsvigorap 900 firmware1 CVEsvigorap 9021 CVEsvigorap 902 firmware1 CVEsvigorswitch pq2121x1 CVEsvigorswitch pq2121x firmware1 CVEsvigorap 9061 CVEsvigorap 906 firmware1 CVEsvigor2860ac1 CVEsvigor2765va firmware1 CVEsvigorswitch pq2200xb1 CVEsvigorswitch pq2200xb firmware1 CVEsvigorswitch q2121x1 CVEsvigorswitch q2121x firmware1 CVEsvigorap 920r1 CVEsvigorap 920r firmware1 CVEsvigorap 960c1 CVEsvigorap 960c firmware1 CVEsvigor2765va1 CVEsvigor2625 firmware1 CVEsvigor26251 CVEsvigorswitch q2200x1 CVEsvigorswitch q2200x firmware1 CVEsvigornic 1321 CVEsvigornic 132 firmware1 CVEsvigorswitch fx21201 CVEsvigorswitch fx2120 firmware1 CVEsvigorswitch g10801 CVEsvigorswitch g1080 firmware1 CVEsvigorswitch g10851 CVEsvigorswitch g1085 firmware1 CVEsvigorswitch g12821 CVEsvigorswitch g1282 firmware1 CVEsvigorswitch g21001 CVEsvigorswitch g2100 firmware1 CVEsvigorswitch g21211 CVEsvigorswitch g2121 firmware1 CVEsvigorswitch g2280x1 CVEsvigor2926 plus firmware1 CVEsvigor2926 plus1 CVEsvigor2925vn-plus firmware1 CVEsvigor2925vac firmware1 CVEsvigorswitch g2280x firmware1 CVEsvigorswitch g2540xs1 CVEsvigor2925n firmware1 CVEsvigor2925n-plus firmware1 CVEsvigor2925n1 CVEsvigor2925ln firmware1 CVEsvigor2925ln1 CVEsvigor2925l firmware1 CVEsvigor2925l1 CVEsvigor2925fn firmware1 CVEsvigorswitch g2540xs firmware1 CVEsvigorswitch p12821 CVEsvigor2925ac firmware1 CVEsvigor2860vn-plus firmware1 CVEsvigor2860vn-plus1 CVEs

Recent Vulnerabilities

View all 134
CVE-2026-3040MEDIUM 4.7

A vulnerability was identified in DrayTek Vigor 300B up to 1.5.1.6. This affects the function cgiGetFile of the file /cgi-bin/mainfunction.cgi/uploadlangs of the component Web Management Interface. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit is publicly available and might be used. The vendor confirms that "300B is EoL, and this is an authenticated vulnerability. We don't plan to fix it." This vulnerability only affects products that are no longer supported by the maintainer.

CVE-2024-51139CRITICAL 9.8

Buffer Overflow vulnerability in Vigor2620/LTE200 3.9.8.9 and earlier and Vigor2860/2925 3.9.8 and earlier and Vigor2862/2926 3.9.9.5 and earlier and Vigor2133/2762/2832 3.9.9 and earlier and Vigor165/166 4.2.7 and earlier and Vigor2135/2765/2766 4.4.5.1 and earlier and Vigor2865/2866/2927 4.4.5.3 and earlier and Vigor2962/3910 4.3.2.8/4.4.3.1 and earlier and Vigor3912 4.3.6.1 and earlier allows a remote attacker to execute arbitrary code via the CGI parser's handling of the "Content-Length" header of HTTP POST requests.

CVE-2024-51138CRITICAL 9.8

Vigor165/166 4.2.7 and earlier; Vigor2620/LTE200 3.9.8.9 and earlier; Vigor2860/2925 3.9.8 and earlier; Vigor2862/2926 3.9.9.5 and earlier; Vigor2133/2762/2832 3.9.9 and earlier; Vigor2135/2765/2766 4.4.5. and earlier; Vigor2865/2866/2927 4.4.5.3 and earlier; Vigor2962 4.3.2.8 and earlier; Vigor3912 4.3.6.1 and earlier; Vigor3910 4.4.3.1 and earlier a stack-based buffer overflow vulnerability has been identified in the URL parsing functionality of the TR069 STUN server. This flaw occurs due to insufficient bounds checking on the amount of URL parameters, allowing an attacker to exploit the overflow by sending a maliciously crafted request. Consequently, a remote attacker can execute arbitrary code with elevated privileges.

CVE-2024-41340HIGH 8.4

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution.

CVE-2024-41339HIGH 8.8

An issue in the CGI endpoint used to upload configurations in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload a crafted kernel module, allowing for arbitrary code execution.

CVE-2024-41338HIGH 7.5

A NULL pointer dereference in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to cause a Denial of Service (DoS) via a crafted DHCP request.

CVE-2024-41334HIGH 8.8

Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 were discovered to not utilize certificate verification, allowing attackers to upload crafted APPE modules from non-official servers, leading to arbitrary code execution.

CVE-2024-12987HIGH 7.3KEV

A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The manipulation of the argument session leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2024-12986HIGH 7.3

A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. The manipulation of the argument session leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.

CVE-2024-45893HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMOption.`

CVE-2024-45891HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_wlan_profile.`

CVE-2024-45890HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `download_ovpn.`

CVE-2024-45889HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `commandTable.`

CVE-2024-45888HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `set_ap_map_config.'

CVE-2024-45887HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `doOpenVPN.`

CVE-2024-45885HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `autodiscovery_clear.`

CVE-2024-45884HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a post-authentication command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `setSWMGroup.`

CVE-2024-45882HIGH 8.0

DrayTek Vigor3900 1.5.1.3 contains a command injection vulnerability. This vulnerability occurs when the `action` parameter in `cgi-bin/mainfunction.cgi` is set to `delete_map_profile.`

CVE-2024-51253HIGH 8.0

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doL2TP function.

CVE-2024-51251HIGH 8.0

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the backup function.

CVE-2024-51249HIGH 8.0

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reboot function.

CVE-2024-51246HIGH 8.0

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPTP function.

CVE-2024-51252CRITICAL 9.8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.

CVE-2024-51248HIGH 8.8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.

CVE-2024-51247HIGH 8.8

In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.