← Back to browse · API

CVE-2022-32548

Severity
CRITICAL
CVSS
10.0
EPSS
0.33795
Risk score
51.83
CISA KEV
No
PoC
No
Published
2022-08-29
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-35616, GHSA-R59X-897W-8H5J
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-35616

Description

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.

References