CVE-2022-32548 is a critical buffer overflow vulnerability affecting DrayTek Vigor routers, specifically versions before July 2022 (e.g., Vigor3910 before 4.3.1.1). This flaw allows unauthenticated attackers to achieve remote code execution by sending specially crafted usernames or passwords to the /cgi-bin/wlogin.cgi endpoint. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise of confidentiality, integrity, and availability. While there is no public exploit code (Metasploit, Nuclei, ExploitDB) or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness and potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.1.1CPE matchmatch criteria | cpe:2.3:o:draytek:vigor3910_firmware:*:*:*:*:*:*:*:* | ||
< 4.3.1.1CPE matchmatch criteria | cpe:2.3:o:draytek:vigor1000b_firmware:*:*:*:*:*:*:*:* | ||
< 4.3.1.1CPE matchmatch criteria | cpe:2.3:o:draytek:vigor2962_firmware:*:*:*:*:*:*:*:* | ||
< 4.3.1.1CPE matchmatch criteria | cpe:2.3:o:draytek:vigor2962p_firmware:*:*:*:*:*:*:*:* | ||
< 4.4.0CPE matchmatch criteria | cpe:2.3:o:draytek:vigor2927_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022DrayTek Router unauthenticated remote code execution vulnerability (CVE-2022-32548)
Aug 4, 2022