CVE-2024-41585

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
03/10/2024
Last modified:
10/04/2025

Description

DrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvCmd binary to escape from the emulated instance and inject arbitrary commands into the host machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:* 4.3.2.6 (including)
cpe:2.3:h:draytek:vigor3910:-:*:*:*:*:*:*:*