CVE-2024-23721

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
20/03/2024
Last modified:
23/05/2025

Description

A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:* 4.3.2.5 (including)
cpe:2.3:h:draytek:vigor3910:-:*:*:*:*:*:*:*