CVE-2024-51139 | DrayTek Vigor LTE200 CGI Parser Content-Length buffer overflow (EUVD-2025-5949)
A vulnerability was found in DrayTek Vigor 165, Vigor 166, Vigor 2133, Vigor 2135, Vigor 2620, Vigor 2762, Vigor 2765, Vigor 2766, Vigor 2832, Vigor 2860, Vigor 2862, Vigor 2865, Vigor 2866, Vigor 2925, Vigor 2925, Vigor 2926, Vigor 2927, Vigor 2962, Vigor 3910, Vigor 3912 and Vigor LTE200. It has been classified as critical. Affected is an unknown function of the component CGI Parser. The manipulation of the argument Content-Length leads to buffer overflow.
This vulnerability is traded as CVE-2024-51139. It is possible to launch the attack remotely. There is no exploit available.