DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to change settings or cause a denial of service via .cgi pages because of missing bounds checks on read and write operations.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://www.forescout.com/resources/draytek14-vulnerabilities | broken link |
https://www.forescout.com/resources/draybreak-draytek-research/ | third party advisory |