Vulnerability Monitor

The vendors, products, and vulnerabilities you care about
vigor3900_firmware Vendor: draytek

About This Product

vigor3900_firmware is a software product offered by draytek. This product is widely deployed in production environments, making vulnerability monitoring essential for organizations relying on it. Security vulnerabilities in products of this category can affect system availability, data confidentiality, and integrity across entire networks. The moderate vulnerability count reflects ongoing security research and responsible disclosure practices. Regular assessment of known vulnerabilities and timely patching are fundamental components of responsible system administration for any deployment of this software.

Vulnerability Landscape Summary

SecUtils has identified 48 known vulnerabilities affecting draytek vigor3900_firmware. This includes 19 critical-severity issues and 29 high-severity issues that warrant immediate attention. Vulnerabilities in this product have been disclosed spanning from 2020 to 2024, indicating a recent active security attention.

Known Vulnerabilities
ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2020-8515 2020-02-01 2025-11-07 9.8 10.0 Likely
CVE-2020-10823 2020-03-26 2025-05-05 9.8 7.5 Likely
CVE-2020-10824 2020-03-26 2025-05-05 9.8 7.5 Likely
CVE-2020-10825 2020-03-26 2025-05-05 9.8 7.5 Likely
CVE-2020-10826 2020-03-26 2025-05-05 9.8 10.0 Likely
CVE-2020-10827 2020-03-26 2025-05-05 9.8 7.5 Likely
CVE-2020-10828 2020-03-26 2025-05-05 9.8 7.5 Likely
CVE-2020-14993 2020-06-23 2024-11-21 9.8 7.5 Likely
CVE-2020-14472 2020-06-24 2024-11-21 9.8 7.5 Likely
CVE-2020-14473 2020-06-24 2024-11-21 9.8 7.5 Likely
CVE-2020-15415 2020-06-30 2025-11-07 9.8 7.5 Likely
CVE-2021-42911 2022-03-29 2024-11-21 9.8 7.5 Likely
CVE-2021-43118 2022-03-29 2024-11-21 9.8 7.5 Likely
CVE-2024-43027 2024-08-21 2025-06-03 8.0 - -
CVE-2024-44844 2024-09-06 2024-09-11 8.8 - -
CVE-2024-44845 2024-09-06 2024-09-11 8.8 - -
CVE-2024-46316 2024-10-09 2025-04-10 8.0 - -
CVE-2024-48153 2024-10-14 2025-04-10 9.8 - -
CVE-2024-51304 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51257 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51296 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51298 2024-10-30 2025-04-10 9.8 - -
CVE-2024-51299 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51300 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51301 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51258 2024-10-30 2025-04-10 8.8 - -
CVE-2024-51254 2024-10-31 2025-04-10 8.8 - -
CVE-2024-51259 2024-10-31 2025-04-10 9.8 - -
CVE-2024-51255 2024-10-31 2025-04-10 9.8 - -
CVE-2024-51260 2024-10-31 2025-04-10 9.8 - -
CVE-2024-51244 2024-11-01 2024-11-05 8.8 - -
CVE-2024-51245 2024-11-01 2024-11-05 8.8 - -
CVE-2024-51247 2024-11-01 2024-11-05 8.8 - -
CVE-2024-51248 2024-11-01 2024-11-05 8.8 - -
CVE-2024-51252 2024-11-01 2024-11-05 9.8 - -
CVE-2024-51246 2024-11-04 2025-04-11 8.0 - -
CVE-2024-51249 2024-11-04 2025-04-11 8.0 - -
CVE-2024-51251 2024-11-04 2025-04-10 8.0 - -
CVE-2024-51253 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45882 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45884 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45885 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45887 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45888 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45889 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45890 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45891 2024-11-04 2025-04-10 8.0 - -
CVE-2024-45893 2024-11-04 2025-04-10 8.0 - -

How SecUtils Interprets Product Data

SecUtils normalizes and enriches National Vulnerability Database (NVD) records for draytek vigor3900_firmware by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and structuring the data for rapid analysis and asset correlation. For every vulnerability listed, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference information to enable organizations to prioritize patching and risk assessment efficiently. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for vulnerability management and security operations.