CVE-2022-32548

CRITICALCVSS 9.8/10EPSS 33.79%

Last modified

CVE-2022-32548 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.. EPSS estimates a 33.79% chance of exploitation in the next 30 days.

Description

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
33.79%

98.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DraytekVigor3910 Firmware< 4.3.1.1
DraytekVigor1000b Firmware< 4.3.1.1
DraytekVigor2962 Firmware< 4.3.1.1
DraytekVigor2962p Firmware< 4.3.1.1
DraytekVigor2927 Firmware< 4.4.0
DraytekVigor2927ax Firmware< 4.4.0
DraytekVigor2927ac Firmware< 4.4.0
DraytekVigor2927vac Firmware< 4.4.0
DraytekVigor2927l Firmware< 4.4.0
DraytekVigor2927lac Firmware< 4.4.0
DraytekVigor2915 Firmware< 4.3.3.2
DraytekVigor2915ac Firmware< 4.3.3.2
DraytekVigor2952 Firmware< 3.9.7.2
DraytekVigor2952p Firmware< 3.9.7.2
DraytekVigor3220 Firmware< 3.9.7.2
DraytekVigor2926 Firmware< 3.9.8.1
DraytekVigor2926n Firmware< 3.9.8.1
DraytekVigor2926ac Firmware< 3.9.8.1
DraytekVigor2926vac Firmware< 3.9.8.1
DraytekVigor2926l Firmware< 3.9.8.1
DraytekVigor2926ln Firmware< 3.9.8.1
DraytekVigor2926lac Firmware< 3.9.8.1
DraytekVigor2862 Firmware< 3.9.8.1
DraytekVigor2862n Firmware< 3.9.8.1
DraytekVigor2862ac Firmware< 3.9.8.1
DraytekVigor2862vac Firmware< 3.9.8.1
DraytekVigor2862b Firmware< 3.9.8.1
DraytekVigor2862bn Firmware< 3.9.8.1
DraytekVigor2862l Firmware< 3.9.8.1
DraytekVigor2862ln Firmware< 3.9.8.1
DraytekVigor2862lac Firmware< 3.9.8.1
DraytekVigor2620l Firmware< 3.9.8.1
DraytekVigor2620ln Firmware< 3.9.8.1
DraytekVigorlte 200n Firmware< 3.9.8.1
DraytekVigor2133 Firmware< 3.9.6.4
DraytekVigor2133n Firmware< 3.9.6.4
DraytekVigor2133ac Firmware< 3.9.6.4
DraytekVigor2133vac Firmware< 3.9.6.4
DraytekVigor2133fvac Firmware< 3.9.6.4
DraytekVigor2762 Firmware< 3.9.6.4
DraytekVigor2762n Firmware< 3.9.6.4
DraytekVigor2762ac Firmware< 3.9.6.4
DraytekVigor2762vac Firmware< 3.9.6.4
DraytekVigor165 Firmware< 4.2.4
DraytekVigor166 Firmware< 4.2.4
DraytekVigor2135 Firmware< 4.4.2
DraytekVigor2135ac Firmware< 4.4.2
DraytekVigor2135vac Firmware< 4.4.2
DraytekVigor2135fvac Firmware< 4.4.2
DraytekVigor2765 Firmware< 4.4.2

Showing 50 of 68 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-32548?
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
How severe is CVE-2022-32548?
CVE-2022-32548 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 33.79% probability of exploitation in the next 30 days.
How do I fix CVE-2022-32548?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-32548?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST