- How many CVEs does DrayTek have?
- DrayTek has 137 published CVE records since 2013, including 10 in the last two years.
- How many DrayTek CVEs are in CISA KEV?
- Yes — 5 of DrayTek's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which DrayTek products have the most CVEs?
- The DrayTek products with the most published CVEs are Vigor3910, vigor3910_firmware, vigor3900_firmware, vigor3900, vigor2960_firmware.
- What are the most common weakness types in DrayTek CVEs?
- DrayTek's CVEs most often map to these CWE weakness types: CWE-120 (Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')), CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')).
- Are there public exploits for DrayTek vulnerabilities?
- Yes — 65 of DrayTek's CVEs have a known public exploit.
- How many critical DrayTek vulnerabilities are there?
- DrayTek has 31 critical and 90 high-severity CVEs.
- What is the average severity of DrayTek CVEs?
- The average CVSS base score across DrayTek's scored CVEs is 8.1.