← back
CVE-2022-32548critical

CVE-2022-32548

60Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 10epss 34%
from disclosure to weapon424 days
Published on NVDAug 29
1st PoC+424d
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.