CVE-2022-32548
60Vexday Risk Score
Keep watching. It has a public proof of concept.
ssvc Attendcvss 10epss 34%
from disclosure to weapon424 days
Published on NVDAug 29
1st PoC+424d
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1. /cgi-bin/wlogin.cgi has a buffer overflow via the username or password to the aa or ab field.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Affected products
n/a · n/apublic PoCs found — 1
githubgithub.com/MosaedH/CVE-2022-32548-RCE-POC★ 8⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.