draytek vigor3900 firmware Vulnerabilities
CVE security advisories and vulnerability history for vigor3900 firmware by draytek.
Last updated
Overview
draytek vigor3900 firmware has 48 published CVE records since 2020, of which 2 are in CISA's Known Exploited Vulnerabilities catalog and 44 have a known public exploit. The average CVSS base score across scored CVEs is 8.9.
This page aggregates every publicly disclosed vulnerability (CVE) affecting draytek vigor3900 firmware, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list. Affected platforms include vigor3900.
Severity and exploitation
How the CVSS severity of draytek vigor3900 firmware's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
2
2 of draytek vigor3900 firmware's CVEs are confirmed exploited in the wild.
Public exploits
44
44 of draytek vigor3900 firmware's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every draytek vigor3900 firmware version named in a CVE, then pick one to see only the CVEs that affect it.
Version ranges
- 1.5.1.3 <= v <= 1.5.1.332 CVEs
- >= 1.5.1.330 CVEs
- < 1.5.17 CVEs
- < 1.5.1.13 CVEs
- >= 1.5.1.63 CVEs
- 1.5.1.6 <= v <= 1.5.1.63 CVEs
- < 1.5.1.51 CVE
- < 1.5.1.5_Beta1 CVE
- <= 1.5.1.31 CVE
- 1.4.4 <= v <= 1.4.41 CVE
Fixed in
- 1.5.17 CVEs
- 1.5.1.13 CVEs
- 1.5.1.51 CVE
- 1.5.1.5_Beta1 CVE
48 CVEs
- High · CVSS 8.0EPSS 0.7% (48th pct)2024-11-04
- High · CVSS 8.0EPSS 0.7% (49th pct)2024-11-04
- High · CVSS 8.0EPSS 0.7% (48th pct)2024-11-04
- High · CVSS 8.0EPSS 0.4% (34th pct)2024-11-04
- High · CVSS 8.0EPSS 1.6% (73th pct)2024-11-04
- High · CVSS 8.0EPSS 1.3% (67th pct)2024-11-04
- High · CVSS 8.0EPSS 2.1% (80th pct)2024-11-04
- High · CVSS 8.0EPSS 1.6% (73th pct)2024-11-04
- High · CVSS 8.0EPSS 2.0% (78th pct)2024-11-04
- High · CVSS 8.0EPSS 2.1% (80th pct)2024-11-04
- High · CVSS 8.0EPSS 1.3% (67th pct)2024-11-04
- High · CVSS 8.0EPSS 2.1% (80th pct)2024-11-04
- High · CVSS 8.0EPSS 1.5% (72th pct)2024-11-04
- Critical · CVSS 9.8EPSS 0.8% (52th pct)2024-11-01
- High · CVSS 8.8EPSS 0.8% (52th pct)2024-11-01
- High · CVSS 8.8EPSS 0.8% (52th pct)2024-11-01
- High · CVSS 8.8EPSS 0.8% (52th pct)2024-11-01
- High · CVSS 8.8EPSS 0.8% (52th pct)2024-11-01
- Critical · CVSS 9.8EPSS 0.6% (45th pct)2024-10-31
- Critical · CVSS 9.8EPSS 0.3% (27th pct)2024-10-31
- Critical · CVSS 9.8EPSS 0.4% (30th pct)2024-10-31
- High · CVSS 8.8EPSS 0.4% (34th pct)2024-10-31
- High · CVSS 8.8EPSS 0.6% (45th pct)2024-10-30
- High · CVSS 8.8EPSS 0.6% (45th pct)2024-10-30
- High · CVSS 8.8EPSS 0.6% (45th pct)2024-10-30
- High · CVSS 8.8EPSS 0.6% (45th pct)2024-10-30
- Critical · CVSS 9.8EPSS 0.6% (45th pct)2024-10-30
- High · CVSS 8.8EPSS 0.6% (45th pct)2024-10-30
- High · CVSS 8.8EPSS 0.5% (42th pct)2024-10-30
- High · CVSS 8.8EPSS 0.4% (30th pct)2024-10-30
Showing 30 of 48
Common weakness types
The CWE weakness categories most often found in draytek vigor3900 firmware CVEs. Follow any weakness for its full explanation.
Disclosure activity by year
How many draytek vigor3900 firmware CVEs were published each year.
Other draytek products
Browse vulnerabilities for other products by draytek.
Frequently asked questions
Common questions about draytek vigor3900 firmware vulnerabilities.
- How many CVEs does draytek vigor3900 firmware have?
- draytek vigor3900 firmware has 48 published CVE records since 2020.
- How many draytek vigor3900 firmware CVEs are in CISA KEV?
- Yes — 2 of draytek vigor3900 firmware's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Are there public exploits for draytek vigor3900 firmware vulnerabilities?
- Yes — 44 of draytek vigor3900 firmware's CVEs have a known public exploit.
- Which versions of draytek vigor3900 firmware are affected?
- 14 distinct draytek vigor3900 firmware versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
- What are the most common weakness types in draytek vigor3900 firmware CVEs?
- draytek vigor3900 firmware's CVEs most often map to these CWE weakness types: CWE-78 (Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')), CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection')), CWE-787 (Out-of-bounds Write), CWE-94 (Improper Control of Generation of Code ('Code Injection')).
- How many critical draytek vigor3900 firmware vulnerabilities are there?
- draytek vigor3900 firmware has 19 critical and 29 high-severity CVEs.
- What is the average severity of draytek vigor3900 firmware CVEs?
- The average CVSS base score across draytek vigor3900 firmware's scored CVEs is 8.9.
References
- All draytek vulnerabilities
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track draytek vigor3900 firmware vulnerabilities
Monitor new draytek vigor3900 firmware vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.