CVE Database
/

CVE-2025-10547

Back to search

CVE-2025-10547

Published: Oct 3, 2025

Modified: Nov 4, 2025

PUBLISHED

Description

An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may allow an attacker the ability to perform RCE on the appliance through memory corruption.

VendorProductVersions

DrayTek Corporation

Vigor1000B

affected
0 - < 4.4.5.1

DrayTek Corporation

Vigor2962

affected
0 - < 4.4.5.1

DrayTek Corporation

Vigor3910

affected
0 - < 4.4.3.6

DrayTek Corporation

Vigor3912

affected
0 - < 4.4.5.1

DrayTek Corporation

Vigor2135

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2763

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2765

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2766

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2865

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2865 LTE Series

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2865L-5G Series

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2866

affected
1.0 - < 4.5.1

DrayTek Corporation

Vigor2866 LTE

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2927

affected
0 - < 4.5.1

DrayTek Corporation

Vigor 2927 LTE

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2927L-5G

affected
0 - < 4.5.1

DrayTek Corporation

Vigor2915

affected
0 - < 4.4.6.1

DrayTek Corporation

Vigor2862

affected
0 - < 3.9.9.12

DrayTek Corporation

Vigor2862 LTE

affected
0 - < 3.9.9.12

DrayTek Corporation

Vigor2926

affected
0 - < 3.9.9.12

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now