Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-32548


An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.


Security Impact Summary

This vulnerability carries a CRITICAL severity rating with a CVSS v3.1 score of 10.0, indicating it can be exploited remotely over the network with relatively low complexity without requiring user interaction and does not require pre-existing privileges . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 136 products from draytek, from draytek, from draytek and 133 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2022, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2022-08-29T06:15:09.423

Last Modified

2024-11-21T07:06:36.290

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System draytek vigor3910_firmware < 4.3.1.1 Yes
Hardware draytek vigor3910 - No
Operating System draytek vigor1000b_firmware < 4.3.1.1 Yes
Hardware draytek vigor1000b - No
Operating System draytek vigor2962_firmware < 4.3.1.1 Yes
Hardware draytek vigor2962 - No
Operating System draytek vigor2962p_firmware < 4.3.1.1 Yes
Hardware draytek vigor2962p - No
Operating System draytek vigor2927_firmware < 4.4.0 Yes
Hardware draytek vigor2927 - No
Operating System draytek vigor2927ax_firmware < 4.4.0 Yes
Hardware draytek vigor2927ax - No
Operating System draytek vigor2927ac_firmware < 4.4.0 Yes
Hardware draytek vigor2927ac - No
Operating System draytek vigor2927vac_firmware < 4.4.0 Yes
Hardware draytek vigor2927vac - No
Operating System draytek vigor2927l_firmware < 4.4.0 Yes
Hardware draytek vigor2927l - No
Operating System draytek vigor2927lac_firmware < 4.4.0 Yes
Hardware draytek vigor2927lac - No
Operating System draytek vigor2915_firmware < 4.3.3.2 Yes
Hardware draytek vigor2915 - No
Operating System draytek vigor2915ac_firmware < 4.3.3.2 Yes
Hardware draytek vigor2915ac - No
Operating System draytek vigor2952_firmware < 3.9.7.2 Yes
Hardware draytek vigor2952 - No
Operating System draytek vigor2952p_firmware < 3.9.7.2 Yes
Hardware draytek vigor2952p - No
Operating System draytek vigor3220_firmware < 3.9.7.2 Yes
Hardware draytek vigor3220 - No
Operating System draytek vigor2926_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926 - No
Operating System draytek vigor2926n_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926n - No
Operating System draytek vigor2926ac_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926ac - No
Operating System draytek vigor2926vac_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926vac - No
Operating System draytek vigor2926l_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926l - No
Operating System draytek vigor2926ln_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926ln - No
Operating System draytek vigor2926lac_firmware < 3.9.8.1 Yes
Hardware draytek vigor2926lac - No
Operating System draytek vigor2862_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862 - No
Operating System draytek vigor2862n_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862n - No
Operating System draytek vigor2862ac_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862ac - No
Operating System draytek vigor2862vac_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862vac - No
Operating System draytek vigor2862b_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862b - No
Operating System draytek vigor2862bn_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862bn - No
Operating System draytek vigor2862l_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862l - No
Operating System draytek vigor2862ln_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862ln - No
Operating System draytek vigor2862lac_firmware < 3.9.8.1 Yes
Hardware draytek vigor2862lac - No
Operating System draytek vigor2620l_firmware < 3.9.8.1 Yes
Hardware draytek vigor2620l - No
Operating System draytek vigor2620ln_firmware < 3.9.8.1 Yes
Hardware draytek vigor2620ln - No
Operating System draytek vigorlte_200n_firmware < 3.9.8.1 Yes
Hardware draytek vigorlte_200n - No
Operating System draytek vigor2133_firmware < 3.9.6.4 Yes
Hardware draytek vigor2133 - No
Operating System draytek vigor2133n_firmware < 3.9.6.4 Yes
Hardware draytek vigor2133n - No
Operating System draytek vigor2133ac_firmware < 3.9.6.4 Yes
Hardware draytek vigor2133ac - No
Operating System draytek vigor2133vac_firmware < 3.9.6.4 Yes
Hardware draytek vigor2133vac - No
Operating System draytek vigor2133fvac_firmware < 3.9.6.4 Yes
Hardware draytek vigor2133fvac - No
Operating System draytek vigor2762_firmware < 3.9.6.4 Yes
Hardware draytek vigor2762 - No
Operating System draytek vigor2762n_firmware < 3.9.6.4 Yes
Hardware draytek vigor2762n - No
Operating System draytek vigor2762ac_firmware < 3.9.6.4 Yes
Hardware draytek vigor2762ac - No
Operating System draytek vigor2762vac_firmware < 3.9.6.4 Yes
Hardware draytek vigor2762vac - No
Operating System draytek vigor165_firmware < 4.2.4 Yes
Hardware draytek vigor165 - No
Operating System draytek vigor166_firmware < 4.2.4 Yes
Hardware draytek vigor166 - No
Operating System draytek vigor2135_firmware < 4.4.2 Yes
Hardware draytek vigor2135 - No
Operating System draytek vigor2135ac_firmware < 4.4.2 Yes
Hardware draytek vigor2135ac - No
Operating System draytek vigor2135vac_firmware < 4.4.2 Yes
Hardware draytek vigor2135vac - No
Operating System draytek vigor2135fvac_firmware < 4.4.2 Yes
Hardware draytek vigor2135fvac - No
Operating System draytek vigor2765_firmware < 4.4.2 Yes
Hardware draytek vigor2765 - No
Operating System draytek vigor2765ac_firmware < 4.4.2 Yes
Hardware draytek vigor2765ac - No
Operating System draytek vigor2765vac_firmware < 4.4.2 Yes
Hardware draytek vigor2765vac - No
Operating System draytek vigor2766_firmware < 4.4.2 Yes
Hardware draytek vigor2766 - No
Operating System draytek vigor2766ac_firmware < 4.4.2 Yes
Hardware draytek vigor2766ac - No
Operating System draytek vigor2766vac_firmware < 4.4.2 Yes
Hardware draytek vigor2766vac - No
Operating System draytek vigor2832_firmware < 3.9.6 Yes
Hardware draytek vigor2832 - No
Operating System draytek vigor2865_firmware < 4.4.0 Yes
Hardware draytek vigor2865 - No
Operating System draytek vigor2865ax_firmware < 4.4.0 Yes
Hardware draytek vigor2865ax - No
Operating System draytek vigor2865ac_firmware < 4.4.0 Yes
Hardware draytek vigor2865ac - No
Operating System draytek vigor2865vac_firmware < 4.4.0 Yes
Hardware draytek vigor2865vac - No
Operating System draytek vigor2865l_firmware < 4.4.0 Yes
Hardware draytek vigor2865l - No
Operating System draytek vigor2865lac_firmware < 4.4.0 Yes
Hardware draytek vigor2865lac - No
Operating System draytek vigor2866_firmware < 4.4.0 Yes
Hardware draytek vigor2866 - No
Operating System draytek vigor2866ax_firmware < 4.4.0 Yes
Hardware draytek vigor2866ax - No
Operating System draytek vigor2866ac_firmware < 4.4.0 Yes
Hardware draytek vigor2866ac - No
Operating System draytek vigor2866vac_firmware < 4.4.0 Yes
Hardware draytek vigor2866vac - No
Operating System draytek vigor2866l_firmware < 4.4.0 Yes
Hardware draytek vigor2866l - No
Operating System draytek vigor2866lac_firmware < 4.4.0 Yes
Hardware draytek vigor2866lac - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For draytek's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.