CVE-2024-41585
Severity CVSS v4.0:
Pending analysis
Type:
CWE-78
OS Command Injections
Publication date:
03/10/2024
Last modified:
10/04/2025
Description
DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.
Impact
Base Score 3.x
6.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:* | 4.3.2.6 (including) | |
| cpe:2.3:h:draytek:vigor3910:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



