CVE-2024-23721
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
20/03/2024
Last modified:
23/05/2025
Description
A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports information.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:* | 4.3.2.5 (including) | |
cpe:2.3:h:draytek:vigor3910:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page